LinuxQuestions.org
Go Job Hunting at the LQ Job Marketplace
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices

Reply
 
Search this Thread
Old 10-03-2004, 05:46 AM   #1
shortsword
LQ Newbie
 
Registered: Oct 2004
Location: California, USA
Distribution: Fedora Core 2
Posts: 24

Rep: Reputation: 15
Audit Log Messages "denied"


I have installed a second HD on my HP Pavilion and then put Fedora Core 1 (later 2) on the new HD to temporarily live with Win XP on the original HD.

That was about three months ago and between my day job, vacation, and family duties I am now getting close to the time where I can take the original HP HD out of the machine, repartition and format it and then start the process over again on my daughter's machine.

But, for several days now, I have been noticing messages like this in my boot messages,

audit(1096789074.273:0): avc: denied { transition } for pid=3136 exe=/bin/su path=/usr/X11R6/bin/xauth dev=hdb3 ino=1064988 scontext=user_u:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=process

This is just an example, I am seeing many such messages referencing many inodes (I think, more on that later), and many different executables.

My interpretation of the message above so far is that the executable /bin/su was running as process 3136 and was attempting to do something involving /usr/X11R6/bin/xauth (which I know is inode 1064988 from using ls -i) and that the ability to do this has been denied, and logged by the audit facility.

But, I still do not understand what Linux is trying to tell me.

First, question, does anyone have any idea what my fine OS is trying to tell me?

Second, question, what man/info pages should I be reading to learn what is needed?

My main concern, of course, is to insure myself that the root partition (i.e., hdb3, you might have guessed), is okay and is going to stay that way for the foreseeable future. My second, almost as great concern is to learn what my ignorance has so-far kept me from learning, how serious the root cause is and how big of a problem it is. Of course, ultimately, I would like to fix that root cause and stop the messages from occurring.

Thank you for any and all help.

Third question, what did I not tell you that I should have?

Thanks again,
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
No longer able to log into ssh. Password right but "permission denied" Baix Linux - Software 11 11-21-2008 12:44 PM
/var/log/messages - kernel: audit(1107868785.573:0): avc: denied { getattr } lothario Linux - Security 2 02-10-2005 04:24 AM
What does "SFW2-INext-DROP-DEFLT" in my messages log file mean? TrulyTessa Linux - Networking 11 12-22-2004 09:28 AM
Boot messages not the same as "dmesg" or "/var/log/messages"? massai Linux - General 5 03-10-2004 12:18 AM
"access denied" boot messages/rc5.d Gaetano Linux - Newbie 5 11-27-2003 08:42 AM


All times are GMT -5. The time now is 04:23 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration