Bug 215781 - SELinux prevents postfix from working with cyrus
SELinux prevents postfix from working with cyrus
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
Ben Levenson
Depends On:
  Show dependency treegraph
Reported: 2006-11-15 13:32 EST by Aurelien Bompard
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version: Current
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2007-08-22 10:14:04 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Aurelien Bompard 2006-11-15 13:32:05 EST
Description of problem:
SELinux blocks postfix from delivering messages to cyrus using the lmtp
protocol. I'm having these messages in the audit.log :

type=AVC msg=audit(1163615289.186:35044): avc:  denied  { search } for  pid=738
comm="lmtp" name="lib" dev=sda2 ino=843650
tcontext=system_u:object_r:var_lib_t:s0 tclass=dir
type=SYSCALL msg=audit(1163615289.186:35044): arch=40000003 syscall=102
success=no exit=-13 a0=3 a1=bf8e4650 a2=82fff4 a3=833780 items=0 ppid=32529
pid=738 auid=500 uid=89 gid=89 euid=89 suid=89 fsuid=89 egid=89 sgid=89 fsgid=89
tty=(none) comm="lmtp" exe="/usr/libexec/postfix/lmtp"
subj=user_u:system_r:postfix_smtp_t:s0 key=(null)

Version-Release number of selected component (if applicable):

How reproducible:

Additional info:
I did a fixfiles relabel and restarted postfix and cyrus-imapd to make sure. I
still have the problem.
The distribution is an FC5 yum-upgraded to FC6, but the "fixfiles relabel"
should have taken care of labeling problems
Comment 1 Daniel Walsh 2006-11-28 16:09:08 EST
Fixed in selinux-policy-2.4.5-3.fc6
Comment 2 Daniel Walsh 2007-08-22 10:14:04 EDT
Fixed in current release

Note You need to log in before you can comment on or make changes to this bug.