Fedora Account System
Red Hat Associate
Red Hat Customer
Hello When I try to connect with vpnc thru networkManager it failed due to Selinux. type=AVC msg=audit(1750432256.108:362): avc: denied { execute } for pid=14638 comm="nm-vpnc-service" name="consolehelper" dev="overlay" ino=1867 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=0 type=AVC msg=audit(1750432259.337:363): avc: denied { execute } for pid=14661 comm="nm-vpnc-service" name="consolehelper" dev="overlay" ino=1867 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=0 Running on : State: idle Deployments: ● fedora:fedora/42/x86_64/silverblue Version: 42.20250619.0 (2025-06-19T01:02:28Z) BaseCommit: 4feba8b535612fd1b4107b670878d7fbe15b86872a6ce4f671febd6c9fbd53c4 GPGSignature: Valid signature by B0F4950458F69E1150C6C5EDC8AC4916105EF944 Other issue here : https://discussion.fedoraproject.org/t/vpnc-stopped-working-after-upgrading-to-f42/152254 https://discussion.fedoraproject.org/t/selinux-avc-for-vpn-does-networkmanager-need-access-to-consolehelper/154329 Thanks Reproducible: Always Steps to Reproduce: 1. Configure a vpnc VPN in NetworkManager 2. Try to connect 3. Actual Results: Fail due to selinux AVC Expected Results: No Selinux AVC issue
This is still very broken on Fedora 43 and no way to downgrade to a previous version. There is a bunch of bugs open about this and none seem very active: https://bugzilla.redhat.com/show_bug.cgi?id=2366205 https://bugzilla.redhat.com/show_bug.cgi?id=2366041 https://github.com/fedora-selinux/selinux-policy/issues/2704 Repetition from top post: https://discussion.fedoraproject.org/t/selinux-avc-for-vpn-does-networkmanager-need-access-to-consolehelper/154329 https://discussion.fedoraproject.org/t/vpnc-stopped-working-after-upgrading-to-f42/152254 Since this is the only bug which is reported against NetworkManager-vpnc and this is the place where people are likely to look first, I think this bug should remain open until resolved. Question to the package maintainers here: Is the package working for you? With selinux enabled / enforcing?