SELinux is enabled in the kernel. Working on your staging machine (not production), set up your chroot, label every item like in the main system, chroot the daemon then watch /var/log/audit/audit.log for violations. Cat the log through 'audit2allow' to see what's causing them.
|