LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-23-2007, 04:46 PM   #1
thllgo
Member
 
Registered: Sep 2003
Location: Laurel MD
Posts: 296

Rep: Reputation: 32
RH Linux login u_user:system_r:unconfined_t?


Hello

When I login to a new RH AS4 box I just built I get

Your default context is user_u:system_r:unconfined_t
Do you want to choose a different one.

I have installed the legacy rlogin/rsh daemons and am running NIS. I have set SElinux to permissive. I have setup 4 other boxes and don't get this query. What could I have done wrong this time to get this query. I get it every time I login.

Help
 
Old 08-23-2007, 05:37 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,417
Blog Entries: 55

Rep: Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627
Nothing wrong, it's not an error. It's a question. With the SELinux "targeted" policy everything(?) that isn't defined by rules runs as unconfined_t. Maybe read up on SELinux?
 
Old 08-23-2007, 05:39 PM   #3
thllgo
Member
 
Registered: Sep 2003
Location: Laurel MD
Posts: 296

Original Poster
Rep: Reputation: 32
I checked the targeted policies against the other 4 boxes and it appears to be the same. What I don't understand is why this box asks the question and the other 4 do not.
 
Old 08-23-2007, 05:55 PM   #4
thllgo
Member
 
Registered: Sep 2003
Location: Laurel MD
Posts: 296

Original Poster
Rep: Reputation: 32
I found that by removing the word multiple from the line

session required pam_selinux.so multiple open

in /etc/pam.d/login and /etc/pam.d/remote stopped the question. I don't know why and the other 4 systems have the word multiple in the file. I also don't know if I just broke something else.

I somehow don't think this is the correct way to get rid of the question since the other 4 don't seem to ask this question.
 
Old 08-24-2007, 04:29 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,417
Blog Entries: 55

Rep: Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627
I also don't know if I just broke something else. I somehow don't think this is the correct way to get rid of the question since the other 4 don't seem to ask this question.
I don't think you broke anything. And I don't know in what way the other boxen are different from this one.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How do I remove "Your default context is root:system_r:unconfined_t." when I Telnet? shsaifee Linux - Security 2 06-23-2007 10:59 PM
cannot login to FC3 linux but can login to FC2 linux and windows XP boot powah Linux - General 3 04-18-2006 02:53 PM
netware login using linux - one login? 686plus Linux - Networking 1 01-15-2006 04:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:36 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration