Fedora Account System
Red Hat Associate
Red Hat Customer
Hi, it seems that since f42 vpnc was changed to use consolehelper, this produces selinux denials when used with NetworkManager-vpnc Setting selinux to permissive produces a working vpn connection, the logged denials are the following: May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { execute } for pid=15722 comm="nm-vpnc-service" name="consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { read open } for pid=15722 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { execute_no_trans } for pid=15722 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { map } for pid=15722 comm="vpnc" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { execute } for pid=15722 comm="vpnc" name="userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { read open } for pid=15722 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { execute_no_trans } for pid=15722 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { map } for pid=15722 comm="userhelper" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { read write } for pid=15722 comm="userhelper" name="vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { open } for pid=15722 comm="userhelper" path="/etc/security/console.apps/vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { getattr } for pid=15722 comm="userhelper" path="/etc/security/console.apps/vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15722]: AVC avc: denied { compute_av } for pid=15722 comm="userhelper" scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:security_t:s0 tclass=security permissive=1 May 13 20:10:58 hostname.tld audit[15732]: AVC avc: denied { execute } for pid=15732 comm="nm-vpnc-service" name="consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15732]: AVC avc: denied { read open } for pid=15732 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15732]: AVC avc: denied { execute_no_trans } for pid=15732 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15732]: AVC avc: denied { map } for pid=15732 comm="vpnc" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15732]: AVC avc: denied { execute } for pid=15732 comm="vpnc" name="userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15732]: AVC avc: denied { read open } for pid=15732 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15732]: AVC avc: denied { execute_no_trans } for pid=15732 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15732]: AVC avc: denied { map } for pid=15732 comm="userhelper" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 May 13 20:10:58 hostname.tld audit[15732]: USER_AVC pid=15732 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:NetworkManager_t:s0 msg='avc: denied { rootok } for scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:system_r:NetworkManager_t:s0 tclass=passwd permissive=1 exe="/usr/bin/userhelper" sauid=0 hostname=? addr=? terminal=?' Reproducible: Always Steps to Reproduce: 1. have a vpnc VPN connection managed by NetworkManager 2. connect to it 3. Actual Results: Not working Expected Results: Working
The SELinux policies for vpnc seem to be in the selinux-policy package. Some background why this problem happens now: due to the /usr/(s)bin merge, the vpnc package was slightly re-structured to always use consolehelper - even when called as root (as done by NetworkManager as well). The vpnc binary can be called as follows: - as root - as unprivileged user - via parametrized systemd unit (as root) - by NetworkManager (called as root) Which exact debug information do you need in order to fix the SELinux policies for all of these cases?
Can you try the coprbuilds in https://github.com/fedora-selinux/selinux-policy/pull/2729/checks to see if anything else is needed?
Hi, sorry it took me a while to get back to you. With this policy I still do not get a working vpn connection. When running in permissive I get the following denials: Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc: denied { execute } for pid=4233 comm="nm-vpnc-service" name="consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc: denied { read open } for pid=4233 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc: denied { execute_no_trans } for pid=4233 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc: denied { map } for pid=4233 comm="vpnc" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1 Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc: denied { execute } for pid=4233 comm="vpnc" name="userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc: denied { read open } for pid=4233 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc: denied { execute_no_trans } for pid=4233 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc: denied { map } for pid=4233 comm="userhelper" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1 Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc: denied { read write } for pid=4233 comm="userhelper" name="vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1 Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc: denied { open } for pid=4233 comm="userhelper" path="/etc/security/console.apps/vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1 Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc: denied { getattr } for pid=4233 comm="userhelper" path="/etc/security/console.apps/vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1 Jun 16 21:05:39 hostname.tld audit[4243]: AVC avc: denied { compute_av } for pid=4243 comm="userhelper" scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:security_t:s0 tclass=security permissive=1 selinux-policy-41.43-1.20250611190034417930.pr2729.8.g8e7039c7f.fc42.noarch selinux-policy-targeted-41.43-1.20250611190034417930.pr2729.8.g8e7039c7f.fc42.noarch
*** Bug 2366205 has been marked as a duplicate of this bug. ***
FWIW, I can get it to work using these permissions: module my-vpnc 1.0; require { type consolehelper_exec_t; type userhelper_conf_t; type userhelper_exec_t; type security_t; type NetworkManager_t; type chkpwd_exec_t; class file { execute execute_no_trans getattr map open read write }; class dir search; class security compute_av; class passwd rootok; } #============= NetworkManager_t ============== allow NetworkManager_t chkpwd_exec_t:file execute; allow NetworkManager_t consolehelper_exec_t:file { execute execute_no_trans map open read }; allow NetworkManager_t security_t:security compute_av; allow NetworkManager_t self:passwd rootok; allow NetworkManager_t userhelper_conf_t:dir search; allow NetworkManager_t userhelper_conf_t:file { getattr open read write }; allow NetworkManager_t userhelper_exec_t:file { execute execute_no_trans map open read }; Save the above type enforcements as my-vpnc.te and run the following commands: # checkmodule -Mmo my-vpnc.mod my-vpnc.te # semodule_package -o my-vpnc.pp -m my-vpnc.mod # semodule -i my-vpnc.pp This should persist through reboots, to revert run: # semodule -r my-vpnc One issue that remained is that the vpnc client keeps running when I stop the VPN through NetworkManager, but I'm not sure that is selinux related. This may prevent you from reconnecting because the interface stays in use. To stop vpnc manually, run: # pkill vpnc
This message is a reminder that Fedora Linux 42 is nearing its end of life. Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13. It is Fedora's policy to close all bug reports from releases that are no longer maintained. At that time this bug will be closed as EOL if it remains open with a 'version' of '42'. Package Maintainer: If you wish for this bug to remain open because you plan to fix it in a currently maintained version, change the 'version' to a later Fedora Linux version. Note that the version field may be hidden. Click the "Show advanced fields" button if you do not see it. Thank you for reporting this issue and we are sorry that we were not able to fix it before Fedora Linux 42 is end of life. If you would still like to see this bug fixed and are able to reproduce it against a later version of Fedora Linux, you are encouraged to change the 'version' to a later version prior to this bug being closed.
Hi, This bug is still present on Fedora 44: ``` type=AVC msg=audit(1778073518.929:409): avc: denied { execute } for pid=86774 comm="nm-vpnc-service" name="consolehelper" dev="overlay" ino=1987 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=0 type=AVC msg=audit(1778073518.994:410): avc: denied { execute } for pid=86781 comm="nm-vpnc-service" name="consolehelper" dev="overlay" ino=1987 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=0 ```
Fedora Linux 42 entered end-of-life (EOL) status on 2026-05-27. Fedora Linux 42 is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of Fedora Linux please feel free to reopen this bug against that version. Note that the version field may be hidden. Click the "Show advanced fields" button if you do not see the version field. If you are unable to reopen this bug, please file a new report against an active release. Thank you for reporting this bug and we are sorry it could not be fixed.
Hi, Could this issue be re-opened please? Fedora 44 is still affected. Regards
I can't seem to edit the version, I could only reopen it; @zpytela can you change it for us?
Re-opening again. I set the Fedora version to 44 according to comment #9. At first, I didn't find the option to set the version either. After some searching: it is hidden by default in the edit view but there is a button "Show advanced fields" which makes it visible.
Got the same on Fedora Sway Spin (44). This is after a fresh install, trying to connect a newly created VPNC connection via Networkmanager. I am very new to SELinux so I can only provide the information I gathered by following this guide: https://docs.fedoraproject.org/en-US/quick-docs/selinux-troubleshooting/ >> journalctl -t setroubleshoot: Aug 29 20:26:05 tuxedo setroubleshoot[69065]: SELinux is preventing nm-vpnc-service from execute access on the file /usr/bin/consolehelper. For complete SELinux messages run: sea> Aug 29 20:26:05 tuxedo setroubleshoot[69065]: SELinux is preventing nm-vpnc-service from execute access on the file /usr/bin/consolehelper. >> sealert -l "*" SELinux is preventing nm-vpnc-service from execute access on the file /usr/bin/consolehelper. SELinux is preventing nm-vpnc-service from execute access on the file /usr/bin/consolehelper. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that nm-vpnc-service should be allowed execute access on the consolehelper file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'nm-vpnc-service' --raw | audit2allow -M my-nmvpncservice # semodule -X 300 -i my-nmvpncservice.pp Additional Information: Source Context system_u:system_r:NetworkManager_t:s0 Target Context system_u:object_r:consolehelper_exec_t:s0 Target Objects /usr/bin/consolehelper [ file ] Source nm-vpnc-service Source Path nm-vpnc-service Port <Unknown> Host tuxedo Source RPM Packages Target RPM Packages usermode-1.114-16.fc44.x86_64 SELinux Policy RPM selinux-policy-targeted-44.7-1.fc44.noarch Local Policy RPM selinux-policy-targeted-44.7-1.fc44.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name tuxedo Platform Linux tuxedo 7.1.10-200.fc44.x86_64 #1 SMP PREEMPT_DYNAMIC Sun Aug 23 16:15:11 UTC 2026 x86_64 Alert Count 5 First Seen 2026-08-29 20:25:46 CEST Last Seen 2026-08-30 11:06:46 CEST Local ID 36ff4508-4761-4e43-89b9-f9d04d54c2c4 Raw Audit Messages type=AVC msg=audit(1788080806.814:244): avc: denied { execute } for pid=10703 comm="nm-vpnc-service" name="consolehelper" dev="dm-0" ino=8401 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=0 Hash: nm-vpnc-service,NetworkManager_t,consolehelper_exec_t,file,execute