Hide Forgot
Description of problem: Running: /sbin/ausearch -sv no -m AVC -ts 09/15/2011 15:41:32 SELinux Check: FAIL SELinux AVC messages found: type=1400 audit(1316115719.288:35518): avc: denied { name_bind } for pid=31435 comm="cyrus-master" src=119 scontext=unconfined_u:system_r:cyrus_t:s0 tcontext=system_u:object_r:innd_port_t:s0 tclass=tcp_socket Version-Release number of selected component (if applicable): Name : selinux-policy Arch : noarch Version : 3.7.19 Release : 93.el6_1.7 How reproducible: 50% Steps to Reproduce: 1. tps-rhnqa on cyrus-imapd Actual results: AVC messages found Expected results: no AVC messages found Additional info: Same on rhel5
Why is cyrus-master trying to bind to port 119? Is this something local to the test?
I think it is testing fot the port 119, if is it free or not, because cyrus-imapd is using it for NNTP. But I'm not sure. I can ask devel.
Well if cyrus-master can run as an nntp server then we should probably just allow this access.
Miroslav add corenet_tcp_bind_innd_port(cyrus_t)
It was added to selinux-policy-3.7.19-113.el6.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2011-1511.html