Bug 901495 - no reasonable troubleshooting help for httpd_can_network_connect_db
Summary: no reasonable troubleshooting help for httpd_can_network_connect_db
Keywords:
Status: CLOSED WORKSFORME
Alias: None
Product: Fedora
Classification: Fedora
Component: setroubleshoot
Version: 18
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-01-18 10:21 UTC by udo.rader
Modified: 2013-04-24 19:36 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2013-04-24 19:36:51 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
sealert screenshot showing the problem (120.30 KB, image/png)
2013-01-18 10:21 UTC, udo.rader
no flags Details
audit log excerpt containing the AVC message (553 bytes, text/plain)
2013-01-18 15:02 UTC, udo.rader
no flags Details

Description udo.rader 2013-01-18 10:21:38 UTC
Created attachment 682295 [details]
sealert screenshot showing the problem

after upgrading fom f17 to f18, I got SE alerts about httpd (apache) trying to make a "name_connect", see the attached screenshot.

The issue behind the alert is that apache tries to establish a php-mssql database connection that is prevented by the selinux configuration.

What I expect is to get "real" troubleshooting by sealert and no generic "file a bug if you want to allow httpd making name_connect in tcp ports".

If I open the details of the issue, all required troubleshooting information is there, see the "SETroubleshoot Details Window" in the screenshot again.

Comment 1 Daniel Walsh 2013-01-18 14:54:09 UTC
Strange can you send me the AVC messages and I will try to duplicate.

Comment 2 udo.rader 2013-01-18 15:02:20 UTC
Created attachment 682467 [details]
audit log excerpt containing the AVC message

Comment 3 Daniel Walsh 2013-01-30 18:28:56 UTC
Those AVC's worked fine for me.

If you just cat them into /usr/bin/sedispatch

I get three options.


Note You need to log in before you can comment on or make changes to this bug.