LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat
User Name
Password
Red Hat This forum is for the discussion of Red Hat Linux.

Notices


Reply
  Search this Thread
Old 03-24-2009, 01:28 AM   #1
smoyse
LQ Newbie
 
Registered: Aug 2003
Location: Newcastle, Australia
Distribution: RedHat
Posts: 6

Rep: Reputation: 0
logrotate creates /var/log/messages with the wrong selinux context on RHEL5


When logrotate creates a new /var/log/messages is gets the wrong selinux context ie:

[root@hostname log]# ls -Z messages
-rw------- root root system_ubject_r:file_t:s0 messages
[root@hostname log]# ls -Z messages.1
-rw------- root root system_ubject_r:var_log_t:s0 messages.1

The same is true for other log files (maillog,secure,spooler)

logrotate version: logrotate-3.7.4-8

This behaviour prevents these logs being written when selinux is enabled.

I could potentially use restorecond or a cron job to fix them, but it doesn't seem like the right thing to do.

Steven
 
Old 03-24-2009, 06:46 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Was anything changed in the way logrotate runs?
Was anything changed in /etc/logrotate.d/syslog?
What does 'grep g/messages /etc/selinux/targeted/modules/active/file_contexts' return? I have one entry showing context "var_log_t".
 
Old 03-30-2009, 02:33 AM   #3
smoyse
LQ Newbie
 
Registered: Aug 2003
Location: Newcastle, Australia
Distribution: RedHat
Posts: 6

Original Poster
Rep: Reputation: 0
Thank you for the reply so for being late in replying. The full story is that this machine belongs to a customer of whose previous system administrator has done some things in an attempt to harden the machine. The customer is now asking me to help Put things straight. Still it's a bit of a pain because I have to arrange access before hand.

The answers to your questions are:

Was anything changed in the way logrotate runs? Possibly.

Was anything changed in /etc/logrotate.d/syslog? Doesn't look like it.

[root@hostname etc]# grep g/messages /etc/selinux/targeted/modules/active/file_contexts
/var/log/messages[^/]* system_ubject_r:var_log_t:s0

So I am still a bit lost as to why the context is wrong.

interestingly touch messages creates a file with this context:
-rw-r--r-- root root user_ubject_r:var_log_t:s0 messages


I would be grateful for any more thoughts.

Thanks

Steven
 
Old 03-30-2009, 08:20 PM   #4
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,359

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
Try

restorecon -vvF /var/log/messages
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
/var/log/messages and /var/log/cron not working sigkill Linux - Software 6 08-09-2008 01:08 PM
why runlevel switch message is not logged into /var/log/messages in RHEL5? mnatchad Red Hat 1 05-14-2008 07:11 PM
logrotate and /var/log/btmp msteiner Linux - General 1 06-14-2007 08:31 PM
Redirecting the kernel messages to file other than /var/log/messages jyotika_b83 Linux - General 3 04-28-2005 06:39 PM
Wrong uid in /var/log/messages wfhoney Linux - Security 1 02-12-2004 01:57 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat

All times are GMT -5. The time now is 10:42 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration