Bug 164714 - NM-vpnc does not connect to VPN
Summary: NM-vpnc does not connect to VPN
Alias: None
Product: Fedora
Classification: Fedora
Component: NetworkManager-vpnc (Show other bugs)
(Show other bugs)
Version: rawhide
Hardware: All Linux
Target Milestone: ---
Assignee: David Zeuthen
QA Contact: Fedora Extras Quality Assurance
: 163405 (view as bug list)
Depends On:
TreeView+ depends on / blocked
Reported: 2005-07-30 22:33 UTC by Matthew Saltzman
Modified: 2013-03-06 03:44 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2005-08-02 20:17:51 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

Description Matthew Saltzman 2005-07-30 22:33:37 UTC
Description of problem:
Attempting to connect to a VPN results in an error:

VPN Connect Failure

Could not start the VPN connection '...' due to a connection error.

The VPN service said: "The VPN login failed because the VPN program could not
connect to the VPN server."

Connecting using vpnc directly works fine.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. Create a VPN in nm-applet.
2. Attempt to connect.
Actual results:
The above-mentioned error.

Expected results:
Connection to the VPN.

Additional info:
Using NetworkManager*-0.4-34.cvs20050729.  Cisco airo wireless driver.

Comment 1 David Zeuthen 2005-08-01 15:31:36 UTC
Two questions

1. Does this happen all the time? 
2. Does invoking vpnc from a shell work OK?

Comment 2 David Zeuthen 2005-08-01 15:34:39 UTC
Btw, can you attach the bits of /var/log/messages that is printed during the
connection attempt? Thanks

Comment 3 Matthew Saltzman 2005-08-01 16:06:57 UTC
1. Yes.
2. Yes, as root.  As user, I get "/usr/sbin/vpnc: binding to port 500:
Permission denied".

When I attempt to use NM-vpnc, the only message in /var/log/messages is:

Aug  1 11:52:05 vincent52 NetworkManager: <WARNING>       (): VPN failed for
service 'org.freedesktop.NetworkManager.vpnc', signal 'ConnectFailed', with
message 'The VPN login failed because the VPN program could not connect to the
VPN server.'.

Comment 4 David Zeuthen 2005-08-01 17:29:25 UTC
*** Bug 163405 has been marked as a duplicate of this bug. ***

Comment 5 David Zeuthen 2005-08-01 17:31:18 UTC
Changing version to devel since this is only available in Rawhide / Rawhide Extras.

Comment 6 Christopher Aillon 2005-08-02 14:59:47 UTC
So, further debugging shows that selinux is the culprit here.  This is the
message thrown to /var/log/messages.

Aug  2 10:48:25 dhcp83-16 dbus: avc:  denied  { send_msg } for
msgtype=method_call interface=com.redhat.dhcp member=set dest=com.redhat.dhcp
spid=3511 tpid=3445 scontext=root:system_r:dhcpc_t
tcontext=root:system_r:unconfined_t tclass=dbus

Workaround for this bug is to disable selinux.

Comment 7 Daniel Walsh 2005-08-02 15:33:06 UTC
Fixed in selinux-policy-targeted-1.25.3-11

Comment 8 David Zeuthen 2005-08-02 16:25:47 UTC
Matthew Saltzman, does disabling selinux or updating to
selinux-policy-targeted-1.25.3-11 make this work for you?

Comment 10 Daniel Walsh 2005-08-02 18:54:05 UTC
It is available on ftp://people.redhat.com/dwalsh/Fedora
and will be available via rawhide tomorrow.

Comment 11 Christopher Aillon 2005-08-02 19:17:00 UTC
Make that ftp://people.redhat.com/dwalsh/SELinux/Fedora

Comment 12 Matthew Saltzman 2005-08-02 20:14:46 UTC
Yes, "setenforce 0" works around the problem.  Updating to
selinux-policy-targeted-1.25.3-11 also solves the problem.


Comment 13 David Zeuthen 2005-08-02 20:17:51 UTC
Thanks to everyone involved. Closing this bug.

Note You need to log in before you can comment on or make changes to this bug.