Fedora Account System
Red Hat Associate
Red Hat Customer
Summary: SELinux is preventing /usr/sbin/asterisk "setcap" access. Detailed Description: [asterisk has a permissive type (asterisk_t). This access was not denied.] SELinux denied access requested by asterisk. It is not expected that this access is required by asterisk and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access: You can generate a local policy module to allow this access - see FAQ (http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Please file a bug report. Additional Information: Source Context unconfined_u:system_r:asterisk_t:s0 Target Context unconfined_u:system_r:asterisk_t:s0 Target Objects None [ process ] Source asterisk Source Path /usr/sbin/asterisk Port <Unknown> Host (removed) Source RPM Packages asterisk-1.6.1.9-1.fc12 Target RPM Packages Policy RPM selinux-policy-3.6.32-46.fc12 Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Plugin Name catchall Host Name (removed) Platform Linux (removed) 2.6.31.5-127.fc12.x86_64 #1 SMP Sat Nov 7 21:11:14 EST 2009 x86_64 x86_64 Alert Count 1 First Seen Thu 26 Nov 2009 10:31:48 AM EST Last Seen Thu 26 Nov 2009 10:31:48 AM EST Local ID 1b5d133e-b8ae-44be-8337-f9fe6d223b5b Line Numbers Raw Audit Messages node=(removed) type=AVC msg=audit(1259249508.243:40831): avc: denied { setcap } for pid=29219 comm="asterisk" scontext=unconfined_u:system_r:asterisk_t:s0 tcontext=unconfined_u:system_r:asterisk_t:s0 tclass=process node=(removed) type=SYSCALL msg=audit(1259249508.243:40831): arch=c000003e syscall=126 success=yes exit=0 a0=97bb14 a1=97bb1c a2=2 a3=3b31f27900 items=0 ppid=29218 pid=29219 auid=0 uid=490 gid=477 euid=490 suid=490 fsuid=490 egid=477 sgid=477 fsgid=477 tty=pts0 ses=115 comm="asterisk" exe="/usr/sbin/asterisk" subj=unconfined_u:system_r:asterisk_t:s0 key=(null) Hash String generated from selinux-policy-3.6.32-46.fc12,catchall,asterisk,asterisk_t,asterisk_t,process,setcap audit2allow suggests: #============= asterisk_t ============== allow asterisk_t self:process setcap;
*** This bug has been marked as a duplicate of bug 541658 ***