LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat
User Name
Password
Red Hat This forum is for the discussion of Red Hat Linux.

Notices


Reply
  Search this Thread
Old 03-16-2009, 11:36 AM   #1
TheEngineer
LQ Newbie
 
Registered: Oct 2006
Location: UK
Distribution: MacOS , Redhat
Posts: 17

Rep: Reputation: 0
Angry NTPD and SELINUX problem


Hi.

I'm using RHEL4.x and I've been getting the following error in the /var/log/messages file for a few months or so now and don't know how to resolve the problem.

The error is:

Code:
Mar 16 16:19:19 localhost kernel: audit(1237220359.753:320): avc:  denied  { search } for  pid=8151 comm="ntpd" name="lib" dev=hdb6 ino=1177345 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.753:321): avc:  denied  { search } for  pid=8151 comm="ntpd" name="lib" dev=hdb6 ino=1177345 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.753:322): avc:  denied  { search } for  pid=8151 comm="ntpd" name="lib" dev=hdb6 ino=1177345 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.754:323): avc:  denied  { search } for  pid=8151 comm="ntpd" name="lib" dev=hdb6 ino=1177345 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.754:324): avc:  denied  { search } for  pid=8151 comm="ntpd" name="lib" dev=hdb6 ino=1177345 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.754:325): avc:  denied  { search } for  pid=8151 comm="ntpd" name="lib" dev=hdb6 ino=1177345 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.754:326): avc:  denied  { search } for  pid=8151 comm="ntpd" name="lib" dev=hdb6 ino=1177345 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.754:327): avc:  denied  { search } for  pid=8151 comm="ntpd" name="lib" dev=hdb6 ino=1177345 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.755:328): avc:  denied  { getattr } for  pid=8151 comm="ntpd" name="lib" dev=hdb6 ino=1177345 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.755:329): avc:  denied  { search } for  pid=8151 comm="ntpd" name="tls" dev=hdb6 ino=1444400 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.755:330): avc:  denied  { search } for  pid=8151 comm="ntpd" name="tls" dev=hdb6 ino=1444400 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.755:331): avc:  denied  { search } for  pid=8151 comm="ntpd" name="tls" dev=hdb6 ino=1444400 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost kernel: audit(1237220359.755:332): avc:  denied  { getattr } for  pid=8151 comm="ntpd" name="tls" dev=hdb6 ino=1444400 scontext=root:system_r:ntpd_t tcontext=user_u:object_r:file_t tclass=dir
Mar 16 16:19:19 localhost ntpd: ntpd: error while loading shared libraries: libm.so.6: cannot open shared object file: No such file or directory
Mar 16 16:19:19 localhost ntpd: ntpd startup failed

Has anyone had similar problems and managed to sort it out ??

Thanking you in advance.
 
Old 03-16-2009, 12:23 PM   #2
*******
Member
 
Registered: Feb 2009
Posts: 63

Rep: Reputation: 16
SE Linux Access Vector Cache messages can be dealt with piping them through audit2allow and using the resultant rules to adjust your local policy with.
 
Old 03-17-2009, 06:08 AM   #3
TheEngineer
LQ Newbie
 
Registered: Oct 2006
Location: UK
Distribution: MacOS , Redhat
Posts: 17

Original Poster
Rep: Reputation: 0
Thumbs up

Thanks for the reply.

Before I was going to attempt to use the "audit2allow" command, I decided to try one last thing and managed to sort the problem out by running "system-config-securitylevel" then clicking on the "SELinux" tab and ticking the "Relabel on next reboot" box. When I rebooted, it took a couple of minutes to relabel and then the NTP daemon ran normally...

I did try to use the "restorecon" command several times before but had no luck with it...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SElinux problem palvit Linux - Networking 5 05-03-2008 02:48 PM
Problem at startup with NTPD Dannt Linux - Newbie 9 11-24-2006 10:03 AM
GrSecurity ntpd problem humbletech99 Linux - Security 1 11-19-2005 05:17 AM
SELinux problem stormtracknole Fedora 1 11-12-2005 09:25 AM
ntpd time server problem MGrosskopf Linux - Networking 0 02-06-2005 08:57 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat

All times are GMT -5. The time now is 01:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration