Bug 453844 - Some AVCs regarding ipa_kpasswd
Some AVCs regarding ipa_kpasswd
Status: CLOSED ERRATA
Product: freeIPA
Classification: Community
Component: ipa-server (Show other bugs)
1.0
All Linux
low Severity low
: ---
: ---
Assigned To: Simo Sorce
Chandrasekar Kannan
:
Depends On:
Blocks: 453489
  Show dependency treegraph
 
Reported: 2008-07-02 18:02 EDT by Simo Sorce
Modified: 2015-01-04 18:33 EST (History)
2 users (show)

See Also:
Fixed In Version: freeipa-2.0.0-1.fc15
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Fix selinux policy wrt ipa_kpasswd (1.17 KB, patch)
2008-07-02 18:02 EDT, Simo Sorce
no flags Details | Diff

  None (edit)
Description Simo Sorce 2008-07-02 18:02:09 EDT
Description of problem:

type=1400 audit(1215017904.493:17): avc:  denied  { read } for  pid=2925
comm="ipa_kpasswd" name="net" dev=proc ino=4026531867
scontext=unconfined_u:system_r:ipa_kpasswd_t:s0
tcontext=system_u:object_r:proc_net_t:s0 tclass=lnk_file
type=1400 audit(1215017904.494:18): avc:  denied  { read } for  pid=2925
comm="ipa_kpasswd" name="unix" dev=proc ino=4026533123
scontext=unconfined_u:system_r:ipa_kpasswd_t:s0
tcontext=system_u:object_r:proc_net_t:s0 tclass=file
Comment 1 Simo Sorce 2008-07-02 18:02:45 EDT
Created attachment 310859 [details]
Fix selinux policy wrt ipa_kpasswd
Comment 5 Jenny Galipeau 2008-12-01 14:52:42 EST
Fix Verified or Unable to Reproduce

no selinux avc messages on boot when kpasswd starts:
1) visually on stdout
2) /var/log/dmesg
3) /var/log/messages

Note You need to log in before you can comment on or make changes to this bug.