LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-08-2007, 02:10 PM   #1
ChrisBartram
LQ Newbie
 
Registered: Nov 2007
Posts: 1

Rep: Reputation: 0
Question Can't get snmpd working on selinux system


-Never worked on a selinux enabled box before; seems it's interfering with the snmpd daemon's access to it's config file (/etc/snmp/snmpd.conf).

uname -a
Linux zzz.zzz.zzz 2.6.9-55.0.0.0.2.ELsmp #1 SMP Wed May 2 14:59:56 PDT 2007 i686 i686 i386 GNU/Linux

snmpd -v
NET-SNMP version: 5.1.2

I get the following error when I try to start snmpd;

kernel: audit(1194378789.325:8): avc: denied { read } for pid=4257 comm="snmpd" name="snmpd.conf" dev=dm-0 ino=118759 scontext=root:system_r:snmpd_t tcontext=user_ubject_r:user_home_t tclass=file

I was able to chcon -u root snmpd.conf - but trying to set the role or type gives me a "permission denied". I'm root!?

What am I missing? Or better yet what is the secret incantation I need to get the permissions correct on this file so I can get snmpd running?

TIA,
-Chris
 
Old 09-01-2008, 01:31 AM   #2
VanDaMe
LQ Newbie
 
Registered: Apr 2007
Posts: 20

Rep: Reputation: 0
any solution for this issue?
 
Old 09-01-2008, 03:31 AM   #3
w3bd3vil
Senior Member
 
Registered: Jun 2006
Location: Hyderabad, India
Distribution: Fedora
Posts: 1,191

Rep: Reputation: 49
Add a policy to selinux for snmpd.
you could use system-config-selinux

A tutorial I searched for you
or disable selinux??
Quote:
setenforce 0
 
Old 09-01-2008, 12:24 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by VanDaMe View Post
any solution for this issue?
Please do not resurrect stale threads (over than four to six months old).
The chance you'll get an answer from the OP is rare.
Next time better create your own thread.


Quote:
Originally Posted by w3bd3vil View Post
or disable selinux??
Disabling SE Linux lowers the security posture of the machine.
I would appreciate it if people don't give that kind of "advice".
At least not until all other options have been tested thoroughly.
Thanks for understanding.
 
Old 09-01-2008, 12:46 PM   #5
w3bd3vil
Senior Member
 
Registered: Jun 2006
Location: Hyderabad, India
Distribution: Fedora
Posts: 1,191

Rep: Reputation: 49
Quote:
At least not until all other options have been tested thoroughly.
Yup, I gave him a tutorial to understand if he still couldnt do it, then maybe...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
"../system.h :selinux/selinux.h:no such file or directory" ashmita04 Linux From Scratch 4 02-05-2009 03:36 AM
SELinux: dbus: Can't send to audit system xpucto Linux - Newbie 1 07-05-2007 04:38 PM
New Drive in SeLinux System kromberg Linux - Security 1 04-27-2007 06:02 PM
SElinux // error in file system check // Please Help nomb Fedora 1 03-05-2007 11:51 AM
Anyone actually have anonymous vsftpd working while protected with selinux? ironmike Fedora 5 08-23-2006 09:20 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:36 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration