Re: selinux: rhel5 x fedora 14

2011-01-14 Thread Stephen Smalley
On Thu, 2011-01-13 at 18:21 -0200, Paulo Cavalcanti wrote: > > > On Thu, Jan 13, 2011 at 12:47 PM, Stephen Smalley > wrote: > On Thu, 2011-01-13 at 09:12 -0500, Stephen Smalley wrote: > > On Thu, 2011-01-13 at 11:51 -0200, Paulo Cavalcanti wrote: > > > > > Here it

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Paulo Cavalcanti
On Thu, Jan 13, 2011 at 12:47 PM, Stephen Smalley wrote: > On Thu, 2011-01-13 at 09:12 -0500, Stephen Smalley wrote: > > On Thu, 2011-01-13 at 11:51 -0200, Paulo Cavalcanti wrote: > > > > > Here it goes: > > > > > > > > type=SYSCALL msg=audit(01/13/2011 07:31:09.287:39) : arch=x86_64 > > > s

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Thu, 2011-01-13 at 09:12 -0500, Stephen Smalley wrote: > On Thu, 2011-01-13 at 11:51 -0200, Paulo Cavalcanti wrote: > > > Here it goes: > > > > > type=SYSCALL msg=audit(01/13/2011 07:31:09.287:39) : arch=x86_64 > > syscall=lstat success=no exit=-13(Permission denied) a0=7ff594509d50 > >

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Thu, 2011-01-13 at 11:51 -0200, Paulo Cavalcanti wrote: > > > On Thu, Jan 13, 2011 at 11:28 AM, Stephen Smalley > wrote: > > On Thu, 2011-01-13 at 08:14 -0500, Stephen Smalley wrote: > > On Wed, 2011-01-12 at 21:03 +, Paul Howarth wrote: > > > On Wed, 12 J

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Thu, 2011-01-13 at 11:51 -0200, Paulo Cavalcanti wrote: > Here it goes: > > type=SYSCALL msg=audit(01/13/2011 07:31:09.287:39) : arch=x86_64 > syscall=lstat success=no exit=-13(Permission denied) a0=7ff594509d50 > a1=73924c40 a2=73924c40 a3=2f534d50522f6c6d items=0 ppid=2230 > pi

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Paulo Cavalcanti
On Thu, Jan 13, 2011 at 11:28 AM, Stephen Smalley wrote: > On Thu, 2011-01-13 at 08:14 -0500, Stephen Smalley wrote: > > On Wed, 2011-01-12 at 21:03 +, Paul Howarth wrote: > > > On Wed, 12 Jan 2011 13:02:21 -0500 > > > Daniel J Walsh wrote: > > > > On 01/12/2011 06:29 AM, Paulo Cavalcanti wr

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Thu, 2011-01-13 at 08:14 -0500, Stephen Smalley wrote: > On Wed, 2011-01-12 at 21:03 +, Paul Howarth wrote: > > On Wed, 12 Jan 2011 13:02:21 -0500 > > Daniel J Walsh wrote: > > > On 01/12/2011 06:29 AM, Paulo Cavalcanti wrote: > > > > Hi, > > > > > > > > I have two HDs on my computer: one

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Thu, 2011-01-13 at 08:02 -0200, Paulo Cavalcanti wrote: > > > On Wed, Jan 12, 2011 at 7:07 PM, Daniel J Walsh > wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > > > On 01/12/2011 04:03 PM, Paul Howarth wrote: > > On Wed, 1

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Wed, 2011-01-12 at 21:03 +, Paul Howarth wrote: > On Wed, 12 Jan 2011 13:02:21 -0500 > Daniel J Walsh wrote: > > On 01/12/2011 06:29 AM, Paulo Cavalcanti wrote: > > > Hi, > > > > > > I have two HDs on my computer: one with rhel5 5.5 and the other with > > > fedora 14. > > > Both systems sh

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Paulo Cavalcanti
On Thu, Jan 13, 2011 at 8:02 AM, Paulo Cavalcanti wrote: > > > On Wed, Jan 12, 2011 at 7:07 PM, Daniel J Walsh wrote: > >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> >> On 01/12/2011 04:03 PM, Paul Howarth wrote: >> > On Wed, 12 Jan 2011 13:02:21 -0500 >> > Daniel J Walsh wrote: >> >>

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Paulo Cavalcanti
On Wed, Jan 12, 2011 at 7:07 PM, Daniel J Walsh wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 01/12/2011 04:03 PM, Paul Howarth wrote: > > On Wed, 12 Jan 2011 13:02:21 -0500 > > Daniel J Walsh wrote: > >> On 01/12/2011 06:29 AM, Paulo Cavalcanti wrote: > >>> Hi, > >>> > >>> I h

Re: selinux: rhel5 x fedora 14

2011-01-12 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/12/2011 04:03 PM, Paul Howarth wrote: > On Wed, 12 Jan 2011 13:02:21 -0500 > Daniel J Walsh wrote: >> On 01/12/2011 06:29 AM, Paulo Cavalcanti wrote: >>> Hi, >>> >>> I have two HDs on my computer: one with rhel5 5.5 and the other with >>> fedora

Re: selinux: rhel5 x fedora 14

2011-01-12 Thread Paul Howarth
On Wed, 12 Jan 2011 13:02:21 -0500 Daniel J Walsh wrote: > On 01/12/2011 06:29 AM, Paulo Cavalcanti wrote: > > Hi, > > > > I have two HDs on my computer: one with rhel5 5.5 and the other with > > fedora 14. > > Both systems share some directories located in a common /home, > > mainly used by the

Re: selinux: rhel5 x fedora 14

2011-01-12 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/12/2011 06:29 AM, Paulo Cavalcanti wrote: > Hi, > > I have two HDs on my computer: one with rhel5 5.5 and the other with > fedora 14. > Both systems share some directories located in a common /home, mainly > used by the httpd process. > > The p

Re: selinux: rhel5 x fedora 14

2011-01-12 Thread Stephen Smalley
On Wed, 2011-01-12 at 09:29 -0200, Paulo Cavalcanti wrote: > Hi, > > I have two HDs on my computer: one with rhel5 5.5 and the other with > fedora 14. > Both systems share some directories located in a common /home, mainly > used by the httpd process. > > The problem is that selinux in fedora 14

selinux: rhel5 x fedora 14

2011-01-12 Thread Paulo Cavalcanti
Hi, I have two HDs on my computer: one with rhel5 5.5 and the other with fedora 14. Both systems share some directories located in a common /home, mainly used by the httpd process. The problem is that selinux in fedora 14 uses "unrestricted_u" by default for all users, which rel5 does not underst