LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-26-2017, 11:53 AM   #1
maxfisher
LQ Newbie
 
Registered: Sep 2017
Posts: 2

Rep: Reputation: Disabled
Selinux blocking gpg-agent from read smartcard


I am having a problem with selinux blocking reads to a smartcard from gpg-agent. I know this is the case because with setenforce 0 it works ok but not with setenforce 1.

I have already done the obvious steps to check setroubleshooter and ausearch -c "gpg" --raw | audit2allow -M my-gpg and the same again with "scdaemon" in place of "gpg". When I use ausearch now I don't see any denials for gpg-agent or scdaemon yet the situation remains the same. It works in permissive mode but fails in enforcing mode. What to do next?
 
Old 12-28-2017, 10:55 AM   #2
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,627

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
look up using "se troubleshooter "

and use the "audit2alow " command it suggests
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
gpg / gpg-agent -- Can't connect to /root/.gnupg/S.gpg-agent jrtayloriv Linux - Security 9 06-03-2019 10:06 AM
gpg-agent profile script. Lockywolf Slackware 9 03-13-2016 12:55 PM
many instances of gpg-agent edgjerp Linux - Software 0 11-16-2006 03:11 AM
gpg-agent on Slackware(-current?) - does it work? Yalla-One Slackware 2 05-15-2006 02:57 PM
gpg-agent cbonar Linux - Security 0 12-13-2004 06:56 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration