Bug 697131 - SELinux prevents creation of kickstart profile
Summary: SELinux prevents creation of kickstart profile
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Spacewalk
Classification: Community
Component: Server
Version: 1.3
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Michael Mráka
QA Contact: Red Hat Satellite QA List
URL:
Whiteboard:
Depends On:
Blocks: space15
TreeView+ depends on / blocked
 
Reported: 2011-04-15 23:32 UTC by Jonathan DeHaan
Modified: 2011-07-21 14:43 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2011-07-21 14:43:33 UTC
Embargoed:


Attachments (Terms of Use)

Description Jonathan DeHaan 2011-04-15 23:32:36 UTC
Description of problem:
SELinux in Enforcing mode with the 'targetted' profile prevents creation of a new kickstart profile. Setting SELinux to Permissive allows the kickstart profile to be created.

Version-Release number of selected component (if applicable):
Spacewalk 1.3
Fedora 14 x86_64

How reproducible:
Always

Steps to Reproduce:
1. Install Fedora 14 x86_64, keeping the default SELinux setting of Enorcing
2. Install Spacewalk 1.3
3. Create base channel and kickstart distribution
4. Create kickstart profile
  
Actual results:
500 Internal Error after setting root password for profile. The profile is created in Cobbler, but cannot be managed in Spacewalk.

Expected results:
A profile is created that can be edited in Spacewalk.


Additional info:
/var/log/audit/audit.log:
type=AVC msg=audit(1302910027.295:399): avc:  denied  { getattr } for  pid=12033 comm="cobblerd" path="/var/lib/rhn/kickstarts/wizard/Maximum--1.cfg" dev=dm-0 ino=21104823 scontext=system_u:system_r:cobblerd_t:s0 tcontext=system_u:object_r:var_lib_t:s0 tclass=file

Comment 1 Michael Mráka 2011-05-11 07:13:26 UTC
This issue has been fixed in spacewalk master as a part of bug 702274.

Comment 2 Jan Pazdziora (Red Hat) 2011-07-19 19:36:46 UTC
This bugzilla is currently MODIFIED, so we believe the fix is in the Spacewalk nightly yum repository at http://spacewalk.redhat.com/yum/nightly/

Therefore, moving ON_QA.

Comment 3 Jan Pazdziora (Red Hat) 2011-07-21 14:43:33 UTC
Spacewalk 1.5 was released.


Note You need to log in before you can comment on or make changes to this bug.