Bug 508394 - SELinux problem with satidmap.pl on s390x
Summary: SELinux problem with satidmap.pl on s390x
Keywords:
Status: CLOSED DUPLICATE of bug 505606
Alias: None
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Other
Version: 530
Hardware: s390x
OS: Linux
low
medium
Target Milestone: ---
Assignee: Jan Pazdziora
QA Contact: Brandon Perkins
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-06-26 21:02 UTC by John Matthews
Modified: 2009-07-14 15:15 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-06-29 07:07:57 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description John Matthews 2009-06-26 21:02:54 UTC
Description of problem:

Installed on s390x
WebUI is not coming up, checked httpd and saw

# /etc/init.d/httpd status
httpd dead but subsys locked


# cat /var/log/httpd/error_log 
[Fri Jun 26 16:41:54 2009] [notice] SELinux policy enabled; httpd running as context root:system_r:httpd_t:s0
[Fri Jun 26 16:41:54 2009] [notice] suEXEC mechanism enabled (wrapper: /usr/sbin/suexec)
[Fri Jun 26 16:41:55 2009] [notice] Digest: generating secret for digest authentication ...
[Fri Jun 26 16:41:55 2009] [notice] Digest: done
[Fri Jun 26 16:41:55 2009] [error] (13)Permission denied: mod_rewrite: could not start RewriteMap program /etc/rhn/satellite-httpd/conf/satidmap.pl
Configuration Failed

# grep sat /var/log/audit/audit.log 
type=AVC msg=audit(1246048915.488:171): avc:  denied  { execute } for  pid=5251 comm="httpd" name="satidmap.pl" dev=dm-0 ino=1722743 scontext=root:system_r:httpd_t:s0 tcontext=system_u:object_r:etc_t:s0 tclass=file
type=AVC msg=audit(1246049219.728:176): avc:  denied  { execute } for  pid=5631 comm="httpd" name="satidmap.pl" dev=dm-0 ino=1722743 scontext=root:system_r:httpd_t:s0 tcontext=system_u:object_r:etc_t:s0 tclass=file




Version-Release number of selected component (if applicable):
Satellite-5.3.0-RHEL5-re20090625.0-s390x-embedded-oracle.iso

How reproducible:


Steps to Reproduce:
1.
2.
3.
  
Actual results:


Expected results:


Additional info:
I also saw tomcat had a problem on the restart, not sure if it's related to another SELinux issue or just an intermittent bug that popped up.

Comment 1 John Matthews 2009-06-26 21:07:37 UTC
Executed below and getting further, httpd is running now

chcon system_u:object_r:httpd_sys_script_exec_t /etc/rhn/satellite-httpd/conf/satidmap.pl

Comment 2 Jan Pazdziora 2009-06-29 07:07:57 UTC
Taking and marking as dupe of 505606.

*** This bug has been marked as a duplicate of bug 505606 ***


Note You need to log in before you can comment on or make changes to this bug.