Bug 564167 - SELinux is preventing /usr/sbin/openvpn "append" access on /etc/openvpn/openvpn.log.
Summary: SELinux is preventing /usr/sbin/openvpn "append" access on /etc/openvpn/openv...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: openvpn
Version: 12
Hardware: x86_64
OS: Linux
low
medium
Target Milestone: ---
Assignee: Steven Pritchard
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: setroubleshoot_trace_hash:401b9d0b909...
: 564170 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-02-11 22:47 UTC by Fernando
Modified: 2010-12-03 22:56 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2010-12-03 22:56:02 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Fernando 2010-02-11 22:47:01 UTC
Resumo:

SELinux is preventing /usr/sbin/openvpn "append" access on
/etc/openvpn/openvpn.log.

Descrição Detalhada:

SELinux denied access requested by openvpn. It is not expected that this access
is required by openvpn and this access may signal an intrusion attempt. It is
also possible that the specific version or configuration of the application is
causing it to require additional access.

A Permitir o Acesso:

You can generate a local policy module to allow this access - see FAQ
(http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Please file a bug
report.

Informação Adicional:

Contexto de Origem            system_u:system_r:openvpn_t:s0
Contexto de Destino           unconfined_u:object_r:openvpn_etc_t:s0
Objectos de Destino           /etc/openvpn/openvpn.log [ file ]
Fonte                         openvpn
Caminho de Origem             /usr/sbin/openvpn
Porto                         <Desconhecida>
Máquina                      (removed)
Pacotes RPM Fonte             openvpn-2.1-0.37.rc20.fc12
Pacotes RPM Destino           
RPM da Política              selinux-policy-3.6.32-82.fc12
Selinux Activo                True
Tipo de Política             targeted
MLS Activo                    True
Modo de Execução Forçada   Enforcing
Nome do Plugin                catchall
Nome da Máquina              (removed)
Plataforma                    Linux (removed) 2.6.31.5-127.fc12.x86_64 #1 SMP
                              Sat Nov 7 21:11:14 EST 2009 x86_64 x86_64
Contador de Alertas           1
Primeira Vez Visto            Qui 11 Fev 2010 22:27:50 WET
Última Vez Visto             Qui 11 Fev 2010 22:27:50 WET
ID Local                      0cab2f6d-b216-4747-88ed-755a9340103c
Números de Linha             

Mensagens de Auditoria em Bru 

node=(removed) type=AVC msg=audit(1265927270.468:10): avc:  denied  { append } for  pid=929 comm="openvpn" name="openvpn.log" dev=sda2 ino=40021 scontext=system_u:system_r:openvpn_t:s0 tcontext=unconfined_u:object_r:openvpn_etc_t:s0 tclass=file

node=(removed) type=SYSCALL msg=audit(1265927270.468:10): arch=c000003e syscall=2 success=no exit=-13 a0=af26c8 a1=441 a2=180 a3=3b0231d180 items=0 ppid=922 pid=929 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="openvpn" exe="/usr/sbin/openvpn" subj=system_u:system_r:openvpn_t:s0 key=(null)



Hash String generated from  selinux-policy-3.6.32-82.fc12,catchall,openvpn,openvpn_t,openvpn_etc_t,file,append
audit2allow suggests:

#============= openvpn_t ==============
allow openvpn_t openvpn_etc_t:file append;

Comment 1 Miroslav Grepl 2010-02-12 09:25:22 UTC
Why are openvpn log files located under /etc/openvpn directory?

Comment 2 Miroslav Grepl 2010-02-12 09:25:55 UTC
*** Bug 564170 has been marked as a duplicate of this bug. ***

Comment 3 Bug Zapper 2010-11-03 22:20:43 UTC
This message is a reminder that Fedora 12 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 12.  It is Fedora's policy to close all
bug reports from releases that are no longer maintained.  At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '12'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 12's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 12 is end of life.  If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora please change the 'version' of this 
bug to the applicable version.  If you are unable to change the version, 
please add a comment here and someone will do it for you.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 4 Bug Zapper 2010-12-03 22:56:02 UTC
Fedora 12 changed to end-of-life (EOL) status on 2010-12-02. Fedora 12 is 
no longer maintained, which means that it will not receive any further 
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
Fedora please feel free to reopen this bug against that version.

Thank you for reporting this bug and we are sorry it could not be fixed.


Note You need to log in before you can comment on or make changes to this bug.