Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: Hi, We had nagios-plugins-ntp-2.2.1-4git.el6 packages on our RHEL6 server and after we updated to the latest version available in EPEL (nagios-plugins-ntp-2.2.1-15.20180725git3429dad.el6), we started having these SELinux denials: ``avc: denied { execute } for pid=24170 comm="check_ntp" name="ntpdate" dev=dm-0 ino=391810 scontext=system_u:system_r:nagios_services_plugin_t:s0 tcontext=system_u:object_r:ntpdate_exec_t:s0 tclass=file`` Here's the SELinux contexts for the files: Before the update: ``` [ubellavance@server ~]$ ll -Z /usr/sbin/ntpdate -rwxr-xr-x. root root system_u:object_r:ntpdate_exec_t:s0 /usr/sbin/ntpdate [ubellavance@server ~]$ ll -Z /usr/lib64/nagios/plugins/check_ntp -rwxr-xr-x. root root system_u:object_r:nagios_services_plugin_exec_t:s0 /usr/lib64/nagios/plugins/check_ntp ``` After the update: ``` [ubellavance@server ~]# ll -Z /usr/sbin/ntpdate -rwxr-xr-x. root root system_u:object_r:ntpdate_exec_t:s0 /usr/sbin/ntpdate [ubellavance@server ~]# ll -Z /usr/lib64/nagios/plugins/check_ntp -rwxr-xr-x. root root system_u:object_r:nagios_services_plugin_exec_t:s0 /usr/lib64/nagios/plugins/check_ntp ``` Version-Release number of selected component (if applicable): 2.2.1-15.20180725git3429dad.el6 How reproducible: Tried on 3 virtual servers, problem occurs. Steps to Reproduce: 1. Install nagios-plugins-ntp-2.2.1-15.20180725git3429dad and nrpe on a server. 2. Configure nrpe to be able to check time with check_ntp command[check_ntp]=/usr/lib64/nagios/plugins/check_ntp -H ntpserver.domain.com 3. From Nagios server, you can configure a check for check_ntp or use the CLI (should be something like /usr/lib/nagios/plugins/check_nrpe -H 192.168.99.8 -c check_ntp) Actual results: It doesn't work as it is blocked by SELinux. SELinux avc messages above. Returns UNKNOWN status to Nagios server. Expected results: Returns real status (OK, Warning, Critical...) Additional info: I have installed the nrpe-selinux package, then restarted nrpe but it didn't change anything. I can't find what's in this policy. I can't find it either on Koji or Bohdi. Is that normal? Full SELinux error message: SELinux is preventing /usr/bin/perl from execute access on the file /usr/sbin/ntpdate. ***** Plugin leaks (86.2 confidence) suggests ****************************** If you want to ignore perl trying to execute access the ntpdate file, because you believe it should not need this access. Then you should report this as a bug. You can generate a local policy module to dontaudit this access. Do # grep /usr/bin/perl /var/log/audit/audit.log | audit2allow -D -M mypol # semodule -i mypol.pp ***** Plugin catchall (14.7 confidence) suggests *************************** If you believe that perl should be allowed execute access on the ntpdate file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # grep check_ntp /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Additional Information: Source Context system_u:system_r:nagios_services_plugin_t:s0 Target Context system_u:object_r:ntpdate_exec_t:s0 Target Objects /usr/sbin/ntpdate [ file ] Source check_ntp Source Path /usr/bin/perl Port <Unknown> Host atq-sa-rh-1.atqlan.agri-tracabilite.qc.ca Source RPM Packages perl-5.10.1-144.el6.x86_64 Target RPM Packages ntpdate-4.2.6p5-15.el6_10.x86_64 Policy RPM selinux-policy-3.7.19-312.el6.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name atq-sa-rh-1.atqlan.agri-tracabilite.qc.ca Platform Linux atq-sa-rh-1.atqlan.agri-tracabilite.qc.ca 2.6.32-754.11.1.el6.x86_64 #1 SMP Tue Jan 22 17:25:23 EST 2019 x86_64 x86_64 Alert Count 7 First Seen Wed May 15 11:50:31 2019 Last Seen Wed May 15 13:35:41 2019 Local ID 84e09a67-b183-48ee-86da-3d75cd51d4b0 Raw Audit Messages type=AVC msg=audit(1557941741.724:103435): avc: denied { execute } for pid=14734 comm="check_ntp" name="ntpdate" dev=dm-0 ino=1211550 scontext=system_u:system_r:nagios_services_plugin_t:s0 tcontext=system_u:object_r:ntpdate_exec_t:s0 tclass=file type=SYSCALL msg=audit(1557941741.724:103435): arch=x86_64 syscall=execve success=no exit=EACCES a0=204ce50 a1=204cd50 a2=204e140 a3=8 items=0 ppid=14733 pid=14734 auid=4294967295 uid=494 gid=488 euid=494 suid=494 fsuid=494 egid=488 sgid=488 fsgid=488 tty=(none) ses=4294967295 comm=check_ntp exe=/usr/bin/perl subj=system_u:system_r:nagios_services_plugin_t:s0 key=(null) Hash: check_ntp,nagios_services_plugin_t,ntpdate_exec_t,file,execute audit2allow #============= nagios_services_plugin_t ============== allow nagios_services_plugin_t ntpdate_exec_t:file execute; audit2allow -R #============= nagios_services_plugin_t ============== allow nagios_services_plugin_t ntpdate_exec_t:file execute; According to https://github.com/nagios-plugins/nagios-plugins/commits/41039cf4029dc37fb6af9724341d3ec0d9f57112/plugins/t/check_ntp.t, this plugin hasn't changed for years. I couldn't set nagios-plugins-ntp as the component, is that normal?
Found something very weird that could explain the problem: "Old" version: [ubellavance@server ~]$ file /usr/lib64/nagios/plugins/check_ntp /usr/lib64/nagios/plugins/check_ntp: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.18, stripped "New" version: [ubellavance@atqextwebapps1 ~]$ file /usr/lib64/nagios/plugins/check_ntp /usr/lib64/nagios/plugins/check_ntp: a /usr/bin/perl -w script text executable It looks like the file that once was a binary, compiled file, is now a perl script. I guess that perl, even called from this script, isn't allowed to access ntpdate, while the binary is.
It's actually the same file as check_ntp.pl: [ubellavance@server1 ~]$ md5sum /usr/lib64/nagios/plugins/check_ntp /usr/lib64/nagios/plugins/check_ntp.pl 62859d1306d7d8b105b5ba4b9031123d /usr/lib64/nagios/plugins/check_ntp 62859d1306d7d8b105b5ba4b9031123d /usr/lib64/nagios/plugins/check_ntp.pl
*** This bug has been marked as a duplicate of bug 1664981 ***