Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 922732 - SELinux prevents openvpn_t to write inside the /var/lib/openvpn directory
SELinux prevents openvpn_t to write inside the /var/lib/openvpn directory
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: selinux-policy (Show other bugs)
6.4
All Linux
unspecified Severity unspecified
: rc
: ---
Assigned To: Miroslav Grepl
Michal Trunecka
:
: 789342 (view as bug list)
Depends On: 922786
Blocks: 985435
  Show dependency treegraph
 
Reported: 2013-03-18 07:45 EDT by Michal Bruncko
Modified: 2014-09-30 19:34 EDT (History)
5 users (show)

See Also:
Fixed In Version: selinux-policy-3.7.19-210.el6
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-11-21 05:20:35 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2013:1598 normal SHIPPED_LIVE selinux-policy bug fix and enhancement update 2013-11-20 16:39:24 EST

  None (edit)
Description Michal Bruncko 2013-03-18 07:45:14 EDT
Description of problem:
I am getting following AVC's:
type=AVC msg=audit(1363303699.629:5): avc:  denied  { read write } for  pid=1394 comm="openvpn" name="ip_persist.dat" dev=dm-5 ino=146 scontext=system_u:system_r:openvpn_t:s0 tcontext=unconfined_u:object_r:var_lib_t:s0 tclass=file

Several points about this:
- yes, directory /var/lib/openvpn is not standard openvpn distrp package directory (is not included within openvpn rpm)
- but this directory makes only sense for me for storing data to which openvpn daemon should be able to both read and write.

In current situation there is no directory suited for storing permanent varied data - i.e. persistent IP pools for OpenVPN clients (openvpn parameter "ifconfig-pool-persist"), user-specific configurations (openvpn parameter "client-config-dir"). Same situation can be aplied once you want to run openvpn in chrooted environment (openvpn parameter "chroot") - it should be pointed to directory with all necessary variable content (IP pools,...). Directory /var/run/openvpn is just not good point for those purposes.

Version-Release number of selected component (if applicable):
openvpn-2.2.2-1.el6.x86_64
selinux-policy-targeted-3.7.19-195.el6_4.3.noarch

Additional notes:
- this bug can be treaded as continuing from Bug #469284.
- look on comment #4: https://bugzilla.redhat.com/show_bug.cgi?id=469284#c4 from David - here is exact recommendation to which I wanted to focus here. We are missing openvpn directory for permanent OpenVPN data.

thanks
Comment 1 Miroslav Grepl 2013-03-18 08:50:29 EDT
It looks more as openvpn bug for now. We have the following labeling


/etc/openvpn(/.*)?              gen_context(system_u:object_r:openvpn_etc_t,s0)
/etc/openvpn/ipp.txt    --      gen_context(system_u:object_r:openvpn_etc_rw_t,s0)
/etc/rc\.d/init\.d/openvpn --   gen_context(system_u:object_r:openvpn_initrc_exec_t,s0)
/usr/sbin/openvpn       --      gen_context(system_u:object_r:openvpn_exec_t,s0)
/var/log/openvpn.*              gen_context(system_u:object_r:openvpn_var_log_t,s0)
/var/run/openvpn(/.*)?          gen_context(system_u:object_r:openvpn_var_run_t,s0)

So if a new dir is needed then it needs to be added to RPM payload and we will need to add labeling.
Comment 2 Michal Bruncko 2013-03-18 08:56:33 EDT
Hi Miroslav,
Should I open a new bugreport for addressing missing directory for openvpn component?
Thanks
Comment 3 Michal Bruncko 2013-03-18 10:19:45 EDT
I've raised #922786 for openvpn component.
Comment 4 Miroslav Grepl 2013-03-19 07:47:41 EDT
Ok.
Comment 5 Miroslav Grepl 2013-07-17 09:30:58 EDT
I added support for

/var/lib/openvpn
Comment 6 Miroslav Grepl 2013-08-06 16:40:06 EDT
*** Bug 789342 has been marked as a duplicate of this bug. ***
Comment 9 errata-xmlrpc 2013-11-21 05:20:35 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2013-1598.html

Note You need to log in before you can comment on or make changes to this bug.