LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 11-25-2009, 04:47 PM   #1
mrmnemo
Member
 
Registered: Aug 2009
Distribution: linux
Posts: 527

Rep: Reputation: 51
SELinux: Retag errors / unconfined_u multiple avc denial


ok details first:
FC11 w/2.6.30
Key services ::
NFS ( For Mac's in the house)
SAMBA ( for win / trying to export NFS to home network as well)
SELinux : Default policy as shipped with FC11
IPTables: Nothing but the basic FC11 generated file using ' firewall [/ INDENT]via the kde gui.

Ok, so here is my problem: I was having issues exporting Samba and NFS shares AFTER allowing both service via the iptables ( checked the actual file for ACCEPT entries)and running >
Code:
sudo chcon -t smaba_share_t /media/storage/albums

sudo setsebool -P samba_export_all_ro on
The odd thing was an error generated after running chcon of "opperation not supported" which makes me wonder if fedora has another way of tagging.
I was able get everything up and running eventually; however, I am still getting alot avc denials ( miss tagged files ) after retagging at reboot.

users are being put into unconfined_u by default ( which from what i have reading kinda mitigates the any advantages of running SELinux). I could use some pointers or a point in the right direction on which way to go with user levels in SELinux as well as addressing the TONZ of avc denials after retag.

Thanks for any help. I couls post some examples of the aduit if it would help. I am just getting used to setting up iptables and account permissions and WHAM...SELinux.
 
Old 11-25-2009, 06:13 PM   #2
mjmwired
Member
 
Registered: Apr 2004
Distribution: CentOS6, CentOS5, F16, F15, Ubuntu, OpenSuse
Posts: 620

Rep: Reputation: 39
This maybe totally silly but you have:
chcon -t smaba_share_t

Is that a typo here, or did you use this on your machine?
 
Old 11-25-2009, 06:37 PM   #3
chrism01
Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Centos 6.5, Centos 5.10
Posts: 16,261

Rep: Reputation: 2028Reputation: 2028Reputation: 2028Reputation: 2028Reputation: 2028Reputation: 2028Reputation: 2028Reputation: 2028Reputation: 2028Reputation: 2028Reputation: 2028
And also
Quote:
• Change file context
• chcon -R -t public_content_t /mydata/html
• Does not persist across a relabel!

• Add new mapping
• semanage fcontext -a -t public_content_t '/mydata/html(/.*)?'

• Apply the policy context to existing files
• restorecon -vvFR /mydata/html
 
1 members found this post helpful.
Old 11-28-2009, 02:43 PM   #4
mrmnemo
Member
 
Registered: Aug 2009
Distribution: linux
Posts: 527

Original Poster
Rep: Reputation: 51
Quote:
Originally Posted by mjmwired View Post
This maybe totally silly but you have:
chcon -t smaba_share_t

Is that a typo here, or did you use this on your machine?
no typo....i screwed up didnt i. either way, i understood about the not carrying across on a retag. I noticed while doing some research that you can edit file tag properties in a way that will duplicate across a retag ( somewhere). I have since canned FEDORA11 and am going back to slack as fedora was really getting on my nerves ( or was it my lack of understanding) Slack just seems more straight forward and the commands seemed to match LPIC exam book better. I do appreciate your showing willingness to help. Maybe i could get you to give me a hand in setting up a fresh install of SELinux on slackware. Would be a learning experiance for me....practice in patience for you- 8)

Also, i noticed your syntax was chcon -R -t vs. chcon -t ( why?)
 
  


Reply

Tags
selinux


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
postfix fails to start: AVC denial tonj Linux - Software 9 09-22-2008 05:18 AM
AVC denial message on FC9 skeletonca Fedora 1 08-02-2008 03:19 PM
SELinux AVC denial: Wireless drops instantly or never connects vprice Linux - Wireless Networking 8 05-04-2008 08:15 AM
AVC Denial alan_ri Fedora 4 03-31-2008 02:25 PM
Nagios - SELinux AVC Denial davethemackem Linux - Software 1 09-26-2007 03:30 PM


All times are GMT -5. The time now is 09:49 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration