LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 05-20-2011, 01:37 PM   #1
lrtward
Member
 
Registered: Feb 2011
Distribution: CentOS, Ubuntu
Posts: 97

Rep: Reputation: 9
Question SELinux permissions


I'm getting the error described in this bug. The fix is described in the bug:

Code:
The following additional SELinux permissions were found to resolve the situation:

samba_domtrans_winbind_helper(httpd_t)
allow httpd_t winbind_helper_t:process signal;
apache_append_log(winbind_helper_t)
I have searched pretty extensively and I don't have a clue what to do with that information. I don't think setsebool is going to help.
Code:
# getsebool -a | grep winbind
winbind_disable_trans --> off
Here's the back story, though I don't think it's necessarily relevant:

I'm trying to set up single-sign-on (SSO) with Apache, Active Directory, and PHP. I'm using mod_auth_ntlm_winbind as described here and here.

The bits and pieces seem to be working together so far. I can do "kinit" and get a kerberos ticket; I can do "net ads join" and join the AD domain; my wbinfo commands suggest that winbind is working.

When I try to view a web page that's in my restricted subdirectory, though, I get a 500 Internal Server error and my error_log shows
Quote:
[Fri May 20 14:16:37 2011] [error] [client 10.112.10.38] (13)Permission denied: couldn't spawn child ntlm helper process: /usr/bin/ntlm_auth
That's the error described in the bug.
 
Old 05-20-2011, 02:55 PM   #2
rhbegin
Member
 
Registered: Oct 2003
Location: Arkansas, NWA
Distribution: Fedora/CentOS/SL6
Posts: 381

Rep: Reputation: 23
Check to see if you have this package installed:

setroubleshoot

Once you get installed run this command:

sudo /usr/bin/sealert -a /var/log/audit/audit.log | less

I have found this most helpful in troubleshooting SELinux denials.

Take note in RHEL6/Scientific Linux 6 the context are different.

See if this helps.
 
1 members found this post helpful.
Old 05-23-2011, 08:59 AM   #3
lrtward
Member
 
Registered: Feb 2011
Distribution: CentOS, Ubuntu
Posts: 97

Original Poster
Rep: Reputation: 9
AWESOME!!! That revealed two errors and the commands necessary to resolve the errors. I'm not familiar with restorecon or chcon so it looks like I have some SELinux reading to do.

I have a new error but I've seen info on it, so I can now keep chipping away until the darn thing works.

I cannot express how much I appreciate your suggestion. All my searches were yielding naught. Thanks again!!!
 
  


Reply

Tags
selinux



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Permissions issues with pam_mkhomedir.so when SELinux set to enforce manyrootsofallevil Linux - Server 4 03-16-2011 06:15 PM
Accidently reset SELINUX context for /var folder permissions....HELP!?!?!? alannerd Linux - Newbie 3 01-30-2011 04:18 PM
SELinux errors, SELinux and wine ziphem Linux - Security 10 01-27-2011 04:15 PM
Selinux-how do i find out what domains have permissions on what type?(selinux policy) vishyc88 Linux - Security 2 11-22-2010 04:27 AM
"../system.h :selinux/selinux.h:no such file or directory" ashmita04 Linux From Scratch 4 02-05-2009 03:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 04:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration