Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1632738

Summary: AVC denials noticed during test execution for ipa-trust functional in FIPS mode.
Product: Red Hat Enterprise Linux 7 Reporter: Nikhil Dehadrai <ndehadra>
Component: selinux-policyAssignee: Lukas Vrabec <lvrabec>
Status: CLOSED DUPLICATE QA Contact: Milos Malik <mmalik>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 7.6CC: lvrabec, mgrepl, mmalik, plautrba, ssekidde, vmojzis
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-09-25 12:27:44 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Nikhil Dehadrai 2018-09-25 12:17:02 UTC
Description of problem:
AVC denials noticed during trust-add process in FIPS mode.

Version-Release number of selected component (if applicable):
selinux-policy-3.13.1-227.el7.noarch

How reproducible:
Always

Steps to Reproduce:
Execute test suite for ipa-trust-functional (USER) in FIPS mode


Actual results:
Info: Searching AVC errors produced since 1537811298.05 (Mon Sep 24 23:18:18 2018)
Searching logs...
Running '/usr/bin/env LC_ALL=en_US.UTF-8 /sbin/ausearch -m AVC -m USER_AVC -m SELINUX_ERR -ts 09/24/2018 23:18:18 < /dev/null >/mnt/testarea/tmp.rhts-db-submit-result.TJKLWB 2>&1'
----
time->Mon Sep 24 23:25:53 2018
type=USER_AVC msg=audit(1537811753.155:283): pid=3993 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc:  received policyload notice (seqno=2)  exe="/usr/bin/dbus-daemon" sauid=81 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:25:54 2018
type=USER_AVC msg=audit(1537811754.704:285): pid=3993 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc:  received policyload notice (seqno=3)  exe="/usr/bin/dbus-daemon" sauid=81 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:25:55 2018
type=USER_AVC msg=audit(1537811755.651:288): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  received policyload notice (seqno=2)  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:25:55 2018
type=USER_AVC msg=audit(1537811755.651:289): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  received policyload notice (seqno=3)  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:25:57 2018
type=USER_AVC msg=audit(1537811757.187:292): pid=3993 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc:  received policyload notice (seqno=4)  exe="/usr/bin/dbus-daemon" sauid=81 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:25:58 2018
type=USER_AVC msg=audit(1537811758.825:294): pid=3993 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc:  received policyload notice (seqno=5)  exe="/usr/bin/dbus-daemon" sauid=81 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:26:05 2018
type=USER_AVC msg=audit(1537811765.538:298): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  received policyload notice (seqno=4)  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:26:05 2018
type=USER_AVC msg=audit(1537811765.539:299): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  received policyload notice (seqno=5)  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:28:15 2018
type=PROCTITLE msg=audit(1537811895.139:438): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811895.139:438): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811895.139:438):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811895.139:438): arch=c000003e syscall=6 success=no exit=-13 a0=7f255308c270 a1=7f255308b140 a2=7f255308b140 a3=b items=1 ppid=1 pid=4983 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811895.139:438): avc:  denied  { getattr } for  pid=4983 comm="java" path="/dev/random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:28:15 2018
type=PROCTITLE msg=audit(1537811895.139:439): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811895.139:439): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811895.139:439):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811895.139:439): arch=c000003e syscall=21 success=no exit=-13 a0=7f254c634320 a1=4 a2=0 a3=b items=1 ppid=1 pid=4983 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811895.139:439): avc:  denied  { read } for  pid=4983 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:28:15 2018
type=PROCTITLE msg=audit(1537811895.139:440): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811895.139:440): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811895.139:440):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811895.139:440): arch=c000003e syscall=21 success=no exit=-13 a0=7f254c634320 a1=4 a2=0 a3=b items=1 ppid=1 pid=4983 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811895.139:440): avc:  denied  { read } for  pid=4983 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:28:15 2018
type=PROCTITLE msg=audit(1537811895.139:441): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811895.139:441): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811895.139:441):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811895.139:441): arch=c000003e syscall=21 success=no exit=-13 a0=7f254c634320 a1=4 a2=0 a3=b items=1 ppid=1 pid=4983 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811895.139:441): avc:  denied  { read } for  pid=4983 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:29:29 2018
type=PROCTITLE msg=audit(1537811969.659:459): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811969.659:459): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811969.659:459):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811969.659:459): arch=c000003e syscall=6 success=no exit=-13 a0=7f5bd4288270 a1=7f5bd4287140 a2=7f5bd4287140 a3=b items=1 ppid=1 pid=5925 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811969.659:459): avc:  denied  { getattr } for  pid=5925 comm="java" path="/dev/random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:29:29 2018
type=PROCTITLE msg=audit(1537811969.659:460): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811969.659:460): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811969.659:460):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811969.659:460): arch=c000003e syscall=21 success=no exit=-13 a0=7f5bcc62fea0 a1=4 a2=0 a3=b items=1 ppid=1 pid=5925 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811969.659:460): avc:  denied  { read } for  pid=5925 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:29:29 2018
type=PROCTITLE msg=audit(1537811969.659:461): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811969.659:461): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811969.659:461):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811969.659:461): arch=c000003e syscall=21 success=no exit=-13 a0=7f5bcc62fea0 a1=4 a2=0 a3=b items=1 ppid=1 pid=5925 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811969.659:461): avc:  denied  { read } for  pid=5925 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:29:29 2018
type=PROCTITLE msg=audit(1537811969.659:462): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811969.659:462): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811969.659:462):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811969.659:462): arch=c000003e syscall=21 success=no exit=-13 a0=7f5bcc62fea0 a1=4 a2=0 a3=b items=1 ppid=1 pid=5925 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811969.659:462): avc:  denied  { read } for  pid=5925 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:29:51 2018
type=PROCTITLE msg=audit(1537811991.097:466): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811991.097:466): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811991.097:466):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811991.097:466): arch=c000003e syscall=6 success=no exit=-13 a0=7f37bfc0c270 a1=7f37bfc0b140 a2=7f37bfc0b140 a3=b items=1 ppid=1 pid=6397 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811991.097:466): avc:  denied  { getattr } for  pid=6397 comm="java" path="/dev/random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:29:51 2018
type=PROCTITLE msg=audit(1537811991.097:467): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811991.097:467): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811991.097:467):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811991.097:467): arch=c000003e syscall=21 success=no exit=-13 a0=7f37b867bf40 a1=4 a2=0 a3=b items=1 ppid=1 pid=6397 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811991.097:467): avc:  denied  { read } for  pid=6397 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:29:51 2018
type=PROCTITLE msg=audit(1537811991.098:468): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811991.098:468): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811991.098:468):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811991.098:468): arch=c000003e syscall=21 success=no exit=-13 a0=7f37b867bf40 a1=4 a2=0 a3=b items=1 ppid=1 pid=6397 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811991.098:468): avc:  denied  { read } for  pid=6397 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:29:51 2018
type=PROCTITLE msg=audit(1537811991.098:469): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537811991.098:469): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537811991.098:469):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537811991.098:469): arch=c000003e syscall=21 success=no exit=-13 a0=7f37b867bf40 a1=4 a2=0 a3=b items=1 ppid=1 pid=6397 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537811991.098:469): avc:  denied  { read } for  pid=6397 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:31:22 2018
type=PROCTITLE msg=audit(1537812082.352:474): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812082.352:474): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812082.352:474):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812082.352:474): arch=c000003e syscall=6 success=no exit=-13 a0=7ff5571a9260 a1=7ff5571a8130 a2=7ff5571a8130 a3=b items=1 ppid=1 pid=7423 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812082.352:474): avc:  denied  { getattr } for  pid=7423 comm="java" path="/dev/random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:31:22 2018
type=PROCTITLE msg=audit(1537812082.352:475): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812082.352:475): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812082.352:475):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812082.352:475): arch=c000003e syscall=21 success=no exit=-13 a0=7ff550632010 a1=4 a2=0 a3=b items=1 ppid=1 pid=7423 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812082.352:475): avc:  denied  { read } for  pid=7423 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:31:22 2018
type=PROCTITLE msg=audit(1537812082.352:476): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812082.352:476): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812082.352:476):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812082.352:476): arch=c000003e syscall=21 success=no exit=-13 a0=7ff550632010 a1=4 a2=0 a3=b items=1 ppid=1 pid=7423 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812082.352:476): avc:  denied  { read } for  pid=7423 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:31:22 2018
type=PROCTITLE msg=audit(1537812082.352:477): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812082.352:477): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812082.352:477):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812082.352:477): arch=c000003e syscall=21 success=no exit=-13 a0=7ff550632010 a1=4 a2=0 a3=b items=1 ppid=1 pid=7423 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812082.352:477): avc:  denied  { read } for  pid=7423 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:31:45 2018
type=PROCTITLE msg=audit(1537812105.925:480): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812105.925:480): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812105.925:480):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812105.925:480): arch=c000003e syscall=6 success=no exit=-13 a0=7f9f62cf2270 a1=7f9f62cf1140 a2=7f9f62cf1140 a3=b items=1 ppid=1 pid=7922 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812105.925:480): avc:  denied  { getattr } for  pid=7922 comm="java" path="/dev/random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:31:45 2018
type=PROCTITLE msg=audit(1537812105.925:481): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812105.925:481): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812105.925:481):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812105.925:481): arch=c000003e syscall=21 success=no exit=-13 a0=7f9f5c644060 a1=4 a2=0 a3=b items=1 ppid=1 pid=7922 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812105.925:481): avc:  denied  { read } for  pid=7922 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:31:45 2018
type=PROCTITLE msg=audit(1537812105.925:482): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812105.925:482): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812105.925:482):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812105.925:482): arch=c000003e syscall=21 success=no exit=-13 a0=7f9f5c644060 a1=4 a2=0 a3=b items=1 ppid=1 pid=7922 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812105.925:482): avc:  denied  { read } for  pid=7922 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:31:45 2018
type=PROCTITLE msg=audit(1537812105.925:483): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812105.925:483): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812105.925:483):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812105.925:483): arch=c000003e syscall=21 success=no exit=-13 a0=7f9f5c644060 a1=4 a2=0 a3=b items=1 ppid=1 pid=7922 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812105.925:483): avc:  denied  { read } for  pid=7922 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:33:00 2018
type=PROCTITLE msg=audit(1537812180.954:495): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812180.954:495): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812180.954:495):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812180.954:495): arch=c000003e syscall=6 success=no exit=-13 a0=7f84be30f270 a1=7f84be30e140 a2=7f84be30e140 a3=b items=1 ppid=1 pid=8960 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812180.954:495): avc:  denied  { getattr } for  pid=8960 comm="java" path="/dev/random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:33:00 2018
type=PROCTITLE msg=audit(1537812180.954:496): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812180.954:496): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812180.954:496):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812180.954:496): arch=c000003e syscall=21 success=no exit=-13 a0=7f84b463c170 a1=4 a2=0 a3=b items=1 ppid=1 pid=8960 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812180.954:496): avc:  denied  { read } for  pid=8960 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:33:00 2018
type=PROCTITLE msg=audit(1537812180.954:497): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812180.954:497): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812180.954:497):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812180.954:497): arch=c000003e syscall=21 success=no exit=-13 a0=7f84b463c170 a1=4 a2=0 a3=b items=1 ppid=1 pid=8960 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812180.954:497): avc:  denied  { read } for  pid=8960 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:33:00 2018
type=PROCTITLE msg=audit(1537812180.954:498): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812180.954:498): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812180.954:498):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812180.954:498): arch=c000003e syscall=21 success=no exit=-13 a0=7f84b463c170 a1=4 a2=0 a3=b items=1 ppid=1 pid=8960 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812180.954:498): avc:  denied  { read } for  pid=8960 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:33:28 2018
type=USER_AVC msg=audit(1537812208.403:503): pid=3993 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc:  received policyload notice (seqno=6)  exe="/usr/bin/dbus-daemon" sauid=81 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:33:29 2018
type=USER_AVC msg=audit(1537812209.957:504): pid=3993 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc:  received policyload notice (seqno=7)  exe="/usr/bin/dbus-daemon" sauid=81 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:33:30 2018
type=USER_AVC msg=audit(1537812210.241:506): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  received policyload notice (seqno=6)  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:33:30 2018
type=USER_AVC msg=audit(1537812210.241:507): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  received policyload notice (seqno=7)  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
----
time->Mon Sep 24 23:36:59 2018
type=PROCTITLE msg=audit(1537812419.167:572): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812419.167:572): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812419.167:572):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812419.167:572): arch=c000003e syscall=6 success=no exit=-13 a0=7f3308908270 a1=7f3308907140 a2=7f3308907140 a3=b items=1 ppid=1 pid=12026 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812419.167:572): avc:  denied  { getattr } for  pid=12026 comm="java" path="/dev/random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:36:59 2018
type=PROCTITLE msg=audit(1537812419.168:573): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812419.168:573): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812419.168:573):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812419.168:573): arch=c000003e syscall=21 success=no exit=-13 a0=7f330064a7f0 a1=4 a2=0 a3=b items=1 ppid=1 pid=12026 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812419.168:573): avc:  denied  { read } for  pid=12026 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:36:59 2018
type=PROCTITLE msg=audit(1537812419.168:574): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812419.168:574): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812419.168:574):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812419.168:574): arch=c000003e syscall=21 success=no exit=-13 a0=7f330064a7f0 a1=4 a2=0 a3=b items=1 ppid=1 pid=12026 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812419.168:574): avc:  denied  { read } for  pid=12026 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
----
time->Mon Sep 24 23:36:59 2018
type=PROCTITLE msg=audit(1537812419.168:575): proctitle=2F7573722F6C69622F6A766D2F6A72652D312E382E302D6F70656E6A646B2F62696E2F6A617661002D4452455354454153595F4C49423D2F7573722F73686172652F6A6176612F72657374656173792D62617365002D446A6176612E6C6962726172792E706174683D2F7573722F6C696236342F6E757877646F672D6A6E69
type=PATH msg=audit(1537812419.168:575): item=0 name="/dev/random" inode=5338 dev=00:05 mode=020666 ouid=0 ogid=0 rdev=01:08 obj=system_u:object_r:random_device_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=CWD msg=audit(1537812419.168:575):  cwd="/usr/share/tomcat"
type=SYSCALL msg=audit(1537812419.168:575): arch=c000003e syscall=21 success=no exit=-13 a0=7f330064a7f0 a1=4 a2=0 a3=b items=1 ppid=1 pid=12026 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="java" exe="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.181.b15-0.el7.x86_64/jre/bin/java" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1537812419.168:575): avc:  denied  { read } for  pid=12026 comm="java" name="random" dev="devtmpfs" ino=5338 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0
Fail: AVC messages found.
Checking for errors...
Using stronger AVC checks.
	Define empty RHTS_OPTION_STRONGER_AVC parameter if this causes any problems.
Running 'cat /mnt/testarea/tmp.rhts-db-submit-result.TJKLWB | /sbin/ausearch -m AVC -m SELINUX_ERR'
Fail: AVC messages found.
Running 'cat %s | /sbin/ausearch -m USER_AVC >/mnt/testarea/tmp.rhts-db-submit-result.A9H2IN 2>&1'
Info: No AVC messages found.
/bin/grep 'avc: ' /mnt/testarea/dmesg.log | /bin/grep --invert-match TESTOUT.log
No AVC messages found in dmesg
Running '/usr/sbin/sestatus'
SELinux status:                 enabled
SELinuxfs mount:                /sys/fs/selinux
SELinux root directory:         /etc/selinux
Loaded policy name:             targeted
Current mode:                   enforcing
Mode from config file:          enforcing
Policy MLS status:              enabled
Policy deny_unknown status:     allowed
Max kernel policy version:      31
Running 'rpm -q selinux-policy || true'
selinux-policy-3.13.1-227.el7.noarch

Expected results:
No AVC messages should be observed.

Additional info:
1. Similar AVC is observed in test execution for 'ipa-trustfunctional (SSH)' test suite.

Comment 2 Milos Malik 2018-09-25 12:21:54 UTC
I believe this bug is a duplicate of BZ#1631666.

Comment 3 Lukas Vrabec 2018-09-25 12:27:44 UTC

*** This bug has been marked as a duplicate of bug 1631666 ***