Bug 210768 - SELinux targeted policy breaks SMB share
SELinux targeted policy breaks SMB share
Status: CLOSED NOTABUG
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
rawhide
All Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
Ben Levenson
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2006-10-14 12:28 EDT by W. Michael Petullo
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2006-10-14 12:58:37 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Audit log -- attempt to mount homes with SELinux enabled (1.07 KB, application/octet-stream)
2006-10-14 12:30 EDT, W. Michael Petullo
no flags Details
Audit log -- attempt to mount shared with SELinux enabled (1.04 KB, application/octet-stream)
2006-10-14 12:32 EDT, W. Michael Petullo
no flags Details
Audit log -- attempt to mount homes with SELinux permissive (6.91 KB, application/octet-stream)
2006-10-14 12:33 EDT, W. Michael Petullo
no flags Details
Audit log -- attempt to mount shared with SELinux permissive (1.05 KB, application/octet-stream)
2006-10-14 12:35 EDT, W. Michael Petullo
no flags Details

  None (edit)
Description W. Michael Petullo 2006-10-14 12:28:06 EDT
Description of problem:
I have two SMB shares, homes and shared.  When SELinux is enforcing its targeted
policy, Samba is unable to export these shares.

Version-Release number of selected component (if applicable):
selinux-policy-targeted-2.3.18-10

How reproducible:
Every time

Steps to Reproduce:
1. Set SELinux to enforce its targeted policy.
2. Attempt to access SMB shares from another computer.
  
Actual results:
The shares cannot be accessed.

Expected results:
The shares should be accessible from a remote machine.

Additional info:
I use Kerberos to authenticate and LDAP for netowrk information.  Everything
works fine when SELinux is in permissive mode.
Comment 1 W. Michael Petullo 2006-10-14 12:30:54 EDT
Created attachment 138511 [details]
Audit log -- attempt to mount homes with SELinux enabled
Comment 2 W. Michael Petullo 2006-10-14 12:32:48 EDT
Created attachment 138512 [details]
Audit log -- attempt to mount shared with SELinux enabled
Comment 3 W. Michael Petullo 2006-10-14 12:33:44 EDT
Created attachment 138513 [details]
Audit log -- attempt to mount homes with SELinux permissive
Comment 4 W. Michael Petullo 2006-10-14 12:35:08 EDT
Created attachment 138514 [details]
Audit log -- attempt to mount shared with SELinux permissive
Comment 5 W. Michael Petullo 2006-10-14 12:58:37 EDT
Oops:

setsebool samba_enable_home_dirs on
chcon -R -t samba_share_t <PATH TO SHARE>

Sorry about the noise.

Note You need to log in before you can comment on or make changes to this bug.