LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-18-2008, 10:45 AM   #1
vonedaddy
Member
 
Registered: Aug 2004
Location: Philadelphia,PA
Posts: 185

Rep: Reputation: 17
selinux killing fail2ban


I have fail2ban setup and working fine, as long as selinux is in permissive mode. When is setenfore 1 I get this error and fail2ban does not work.

Jan 17 23:46:14 bighat setroubleshoot: #012 SELinux is preventing the fail2ban-server from using potentially mislabeled files (<Unknown>).#012 For complete SELinux messages. run sealert -l 5350c578-4956-4f27-a498-aada31c2


Any ideas?


With selinux in enforce mode I am unable to even start the fail2ban service.

[root@bighat fail2ban]# service fail2ban restart
Stopping fail2ban: [ OK ]
Starting fail2ban: [ OK ]
[root@bighat fail2ban]# service fail2ban stop
Stopping fail2ban: [ OK ]
[root@bighat fail2ban]# setenforce 1
[root@bighat fail2ban]# service fail2ban start
Starting fail2ban: [FAILED]
[root@bighat fail2ban]#

Last edited by vonedaddy; 01-18-2008 at 10:54 AM.
 
Old 01-19-2008, 10:06 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by vonedaddy View Post
For complete SELinux messages. run sealert -l 5350c578-4956-4f27-a498-aada31c2

Any ideas?
The AVC message tells you exactly what to run for more information and posting your service start stop information isn't that.
BTW, the fail2ban policy seems to be included in FC7 since march 2007, selinux-policy-2.6.4-66 and up.
 
Old 01-19-2008, 11:18 AM   #3
vonedaddy
Member
 
Registered: Aug 2004
Location: Philadelphia,PA
Posts: 185

Original Poster
Rep: Reputation: 17
Quote:
Originally Posted by unSpawn View Post
The AVC message tells you exactly what to run for more information and posting your service start stop information isn't that.
BTW, the fail2ban policy seems to be included in FC7 since march 2007, selinux-policy-2.6.4-66 and up.
This is what I get when I run that command then it hangs, I dont know if this is normal. Can someone help me?

[root@bighat ~]# sealert -l 5350c578-4956-4f27-a498-aada31c2
Traceback (most recent call last):
File "/usr/bin/sealert", line 714, in on_connection_state_change
errno, streeor = connection_state.get_response()
AttributeError: 'ConnectionState' object has no attribute 'get_response'

[2]+ Stopped sealert -l 5350c578-4956-4f27-a498-aada31c2
[root@bighat ~]#
 
Old 01-19-2008, 08:39 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Are the Setroubleshootd and D-BUS services running?
 
Old 01-19-2008, 11:02 PM   #5
vonedaddy
Member
 
Registered: Aug 2004
Location: Philadelphia,PA
Posts: 185

Original Poster
Rep: Reputation: 17
Quote:
Originally Posted by unSpawn View Post
Are the Setroubleshootd and D-BUS services running?
setroubleshoot is running, D-BUS I am not familiar with but I do not see anything listed in my chkconfig or etc/init.d pertaining to d-bus.

Last edited by vonedaddy; 01-19-2008 at 11:04 PM.
 
Old 01-20-2008, 05:09 PM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Hmm. Then I don't know. Maybe get ona Fedora mailing list with that.
Anything wrt fail2ban in your /var/log/audit/* ?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
fail2ban sshd startup notification pobbz Linux - Software 0 11-22-2007 03:36 AM
Fail2Ban Question nomb Debian 0 05-21-2007 07:28 AM
fail2ban not blocking vsftp samnjugu Linux - Security 1 04-11-2007 02:35 AM
fail2ban and proftpd 1.3 reeseslover531 Linux - Security 4 02-14-2007 07:10 AM
Weird problem with fail2ban miza Linux - Software 0 10-28-2006 09:57 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration