LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 10-21-2009, 12:58 PM   #1
poctob
LQ Newbie
 
Registered: Feb 2006
Location: USA
Posts: 10

Rep: Reputation: 0
auditd won't start from service or /etc/init.d


Hello,

I have a weird problem with auditd, it refuses to start from using service command or from /etc/init.d/. I am running RHEL 5 Desktop.
Code:
[root@rtcs-server BC3]# /sbin/service auditd start
Starting auditd:                                           [FAILED]
Code:
[root@rtcs-server BC3]# /sbin/service auditd start
Starting auditd:                                           [FAILED]
syslog shows the following messages:

Code:
Oct 21 13:47:46 rtcs-server kernel: type=1400 audit(1256147266.623:8): avc:  denied  { dac_override } for  pid=3895 comm="auditd" capability=1 scontext=user_u:system_r:auditd_t:s0 tcontext=user_u:system_r:auditd_t:s0 tclass=capability
Oct 21 13:47:46 rtcs-server kernel: type=1400 audit(1256147266.623:9): avc:  denied  { dac_read_search } for  pid=3895 comm="auditd" capability=2 scontext=user_u:system_r:auditd_t:s0 tcontext=user_u:system_r:auditd_t:s0 tclass=capability
Oct 21 13:47:46 rtcs-server auditd: Could not open dir /var/log/audit (Permission denied)
Oct 21 13:47:46 rtcs-server auditd: The audit daemon is exiting.
However, I can start auditd just fine by calling an executable:
Code:
[root@rtcs-server BC3]# /sbin/auditd
[root@rtcs-server BC3]# /etc/init.d/auditd status
auditd (pid  3938) is running...
[root@rtcs-server BC3]#
Permissions for audit log directory are:
Code:
[root@rtcs-server BC3]# ls -l /var/log/audit
total 4532
-rw-r----- 1 root root 4623267 Oct 21 13:54 audit.log
[root@rtcs-server BC3]# ls -l /var/log/ | grep audit
drw-r----- 2 root root    4096 Oct 19 10:07 audit
Which is 0640 exactly what auditd needs.

Any help would be appreciated.
 
Old 10-21-2009, 01:13 PM   #2
poctob
LQ Newbie
 
Registered: Feb 2006
Location: USA
Posts: 10

Original Poster
Rep: Reputation: 0
It started working after I edited /etc/init.d/auditd. All I did was to put it some tracing echoes. It still works after my edits are removed. I guess it had issues with permissions of the script itself.
 
  


Reply

Tags
auditd, start


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
auditd wont start jonfa Solaris / OpenSolaris 5 06-30-2014 11:16 AM
cannot start /etc/init.d/novell-ZMD service sirray100 SUSE / openSUSE 0 08-21-2006 04:09 AM
service xyz start instead of /etc/init.d/xyz start stefaandk Fedora 3 08-01-2006 08:00 PM
auditd outputting errors at service start & stop cdhgee Fedora 8 08-08-2005 01:22 PM
init.d service start Question casentm Fedora 2 03-20-2005 08:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 10:12 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration