LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-28-2011, 11:50 AM   #1
hop321
LQ Newbie
 
Registered: Sep 2011
Posts: 2

Rep: Reputation: Disabled
With SELinux disabled, there are AVC denied records in the /var/log/messages


This is a record from /var/log/messages

Sep 28 11:22:55 app-srv kernel: type=1400 audit(1316673006.058:21): avc: denied { execmod } for pid=23856 comm="dosmth" path="/home/user/path/some.so.1.0" dev=cciss/c0d0p3 ino=98557 scontext=user_u:system_r:unconfined_t:s0 tcontext=user_ubject_r:user_home_t:s0 tclass=file

I checked sestatus and this is what it returns
[root@app-srv ~]# sestatus
SELinux status: disabled

I guess there is something that I'm missing. Any clues? Is it possible that some process temporarily starts selinux and then stops it? Unfortunately auditd was stopped and I have no log to check. Any ideas?
 
Old 09-28-2011, 02:00 PM   #2
T3RM1NVT0R
Senior Member
 
Registered: Dec 2010
Location: Internet
Distribution: Linux Mint, SLES, CentOS, Red Hat
Posts: 2,385

Rep: Reputation: 477Reputation: 477Reputation: 477Reputation: 477Reputation: 477
@ Reply

Hi there,

Welcome to LQ!!!

Sometime disabling selinux create such issues. I would first give a try by enabling selinux in permissive mode and see if that makes any difference.
 
Old 09-29-2011, 12:09 AM   #3
hop321
LQ Newbie
 
Registered: Sep 2011
Posts: 2

Original Poster
Rep: Reputation: Disabled
Thanks for your reply.

SElinux was disabled 2-3 years ago. In the /var/log/messages log I can see records from a period of one month, mostly September with "avc: denied { execmod }". Could it be an issue that the machine was restarted a couple of months ago?

This is a production server and I want to be sure before I enable SElinux.
 
Old 09-29-2011, 01:39 AM   #4
T3RM1NVT0R
Senior Member
 
Registered: Dec 2010
Location: Internet
Distribution: Linux Mint, SLES, CentOS, Red Hat
Posts: 2,385

Rep: Reputation: 477Reputation: 477Reputation: 477Reputation: 477Reputation: 477
@ Reply

Alright. Are you aware of any changes that were made a month ago? Like kernel upgrade or any other thing. You can look into /var/log/dmesg to see with which settings server rebooted/came up a month ago.

What exactly this application is used for? Any other relevant logs if you can paste will be helpful.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
logrotate creates /var/log/messages with the wrong selinux context on RHEL5 smoyse Red Hat 3 03-30-2009 08:20 PM
RHEL4: auditd writing to /var/log/messages even though it is disabled jgrumbles Linux - Security 5 09-21-2008 02:49 AM
No records in /var/log/messages jmaher Linux - Security 12 09-22-2007 01:23 AM
audit avc: denied messages ? dansawyer Linux - Software 1 09-04-2006 03:44 PM
/var/log/messages - kernel: audit(1107868785.573:0): avc: denied { getattr } lothario Linux - Security 2 02-10-2005 04:24 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:33 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration