LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-18-2010, 01:46 AM   #1
localhost
LQ Newbie
 
Registered: Feb 2003
Location: New Zealand
Posts: 5

Rep: Reputation: 0
selinux and lvm


I have installed CentOS and Redhat5 on a LVM partition and selinux is enabled. Both OS's share the same /home partition with one user with the same login(gc) and same uid (1000). The problem I am having is that gc can login with all permissions etc on the OS that was installed first (CentOS). For the redhat OS gc can login but cannot write to the home directory (or startx since X needs to write to Xauthority)


Here are outputs - 1st CentOS

[gc@shuttle ~]$ ll -Zd $HOME
drwx------ gc gc system_ubject_r:unlabeled_t /home/gc
[gc@shuttle ~]$ stat $HOME
File: `/home/gc'
Size: 4096 Blocks: 8 IO Block: 4096 directory
Device: fd03h/64771d Inode: 300145 Links: 37
Access: (0700/drwx------) Uid: ( 1000/ gc) Gid: ( 1000/ gc)
Access: 2010-10-18 12:50:32.000000000 +1300
Modify: 2010-10-18 12:41:01.000000000 +1300
Change: 2010-10-18 12:41:01.000000000 +1300


and now with redhat5 :-

[gc@shuttle ~]$ ll -Zd $HOME
drwx------ gc gc system_ubject_r:unlabeled_t /home/gc
[gc@shuttle ~]$ stat $HOME
File: `/home/gc'
Size: 4096 Blocks: 8 IO Block: 4096 directory
Device: fd03h/64771d Inode: 300145 Links: 37
Access: (0700/drwx------) Uid: ( 1000/ gc) Gid: ( 1000/ gc)
Access: 2010-10-18 13:01:03.000000000 +1300
Modify: 2010-10-18 12:57:33.000000000 +1300
Change: 2010-10-18 12:57:33.000000000 +1300

both seem to be exactly the same
but under redhat
if i try :-
[gc@shuttle ~]$ touch : > newfile
-bash: newfile: Permission denied

no problem with CentoS

any ideas

thanks

GC
 
Old 10-18-2010, 02:37 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by localhost View Post
unlabeled_t /home/gc
/home has context home_root_t and /home/${LOGNAME} has context user_home_dir_t. If 'chcon home_root_t /home; chcon -R user_home_dir_t/home/${LOGNAME}' works then check your /var/log/audit/audit.log for additional problems and think about relabeling.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Selinux-how do i find out what domains have permissions on what type?(selinux policy) vishyc88 Linux - Security 2 11-22-2010 04:27 AM
Adding an LVM hard disk to a system already running/using LVM firewiz87 Linux - Hardware 5 08-15-2010 12:59 AM
"../system.h :selinux/selinux.h:no such file or directory" ashmita04 Linux From Scratch 4 02-05-2009 03:36 AM
SELinux - disabling in CentOS 5.1 prevents LVM from loading and/or booting tiber Linux - Software 2 02-09-2008 04:51 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration