Re: selinux.... again[SOLVED (for ahow long?]

2020-03-06 Thread Samuel Sieb
On 3/6/20 10:06 AM, François Patte wrote: Why suddenly, selinux stopped to allow dictd to use map access to this file? (I recall that I did not change anything to the dictd config) Possibly an selinux policy update either in the general one or the dictd specific one. How long this solution

Re: selinux.... again[SOLVED (for ahow long?]

2020-03-06 Thread François Patte
Le 05/03/2020 à 22:59, Samuel Sieb a écrit : > On 3/5/20 1:30 PM, François Patte wrote: >> Le 05/03/2020 à 22:00, Samuel Sieb a écrit : >>> What is the output of "ls -lZ /var/lib/rpm". >> >> total 126120 >> -rw-r--r--. 1 root root unconfined_u:object_r:var_lib_t:s0  16687104  5 >> mars  11:47 Basen

Re: selinux.... again

2020-03-05 Thread Ed Greshko
On 2020-03-06 05:43, François Patte wrote: > Le 05/03/2020 à 21:52, Ed Greshko a écrit : >> >> fixfiles onboot > This did not fix the problem! > I don't know if it would have made a difference but I should have included -F in the fixfiles options. -- The key to getting good answers is to ask go

Re: selinux.... again

2020-03-05 Thread Samuel Sieb
On 3/5/20 1:30 PM, François Patte wrote: Le 05/03/2020 à 22:00, Samuel Sieb a écrit : What is the output of "ls -lZ /var/lib/rpm". total 126120 -rw-r--r--. 1 root root unconfined_u:object_r:var_lib_t:s0 16687104 5 mars 11:47 Basenames Was this before or after the fixfiles? It should be:

Re: selinux.... again

2020-03-05 Thread Ed Greshko
On 2020-03-06 05:43, François Patte wrote: > Le 05/03/2020 à 21:52, Ed Greshko a écrit : >> On 2020-03-06 01:15, François Patte wrote: >>> Le 05/03/2020 à 14:16, Ed Greshko a écrit : On 2020-03-05 21:02, François Patte wrote: > Le 05/03/2020 à 13:53, Ed Greshko a écrit : >> When the se

Re: selinux.... again

2020-03-05 Thread François Patte
Le 05/03/2020 à 21:52, Ed Greshko a écrit : > On 2020-03-06 01:15, François Patte wrote: >> Le 05/03/2020 à 14:16, Ed Greshko a écrit : >>> On 2020-03-05 21:02, François Patte wrote: Le 05/03/2020 à 13:53, Ed Greshko a écrit : > When the server fails to start with selinux enabled what do y

Re: selinux.... again

2020-03-05 Thread François Patte
Le 05/03/2020 à 22:00, Samuel Sieb a écrit : > On 3/5/20 9:15 AM, François Patte wrote: >> Le 05/03/2020 à 14:16, Ed Greshko a écrit : >>> On 2020-03-05 21:02, François Patte wrote: Le 05/03/2020 à 13:53, Ed Greshko a écrit : > When the server fails to start with selinux enabled what do yo

Re: selinux.... again

2020-03-05 Thread Samuel Sieb
On 3/5/20 9:15 AM, François Patte wrote: Le 05/03/2020 à 14:16, Ed Greshko a écrit : On 2020-03-05 21:02, François Patte wrote: Le 05/03/2020 à 13:53, Ed Greshko a écrit : When the server fails to start with selinux enabled what do you get with ausearch -m AVC,USER_AVC -ts recent [root@dipa

Re: selinux.... again

2020-03-05 Thread Ed Greshko
On 2020-03-06 01:15, François Patte wrote: > Le 05/03/2020 à 14:16, Ed Greshko a écrit : >> On 2020-03-05 21:02, François Patte wrote: >>> Le 05/03/2020 à 13:53, Ed Greshko a écrit : When the server fails to start with selinux enabled what do you get with ausearch -m AVC,USER_AVC -ts

Re: selinux.... again

2020-03-05 Thread François Patte
Le 05/03/2020 à 14:16, Ed Greshko a écrit : > On 2020-03-05 21:02, François Patte wrote: >> Le 05/03/2020 à 13:53, Ed Greshko a écrit : >>> When the server fails to start with selinux enabled what do you get with >>> >>> ausearch -m AVC,USER_AVC -ts recent >>> >> [root@dipankar ~]# ausearch -m AVC,

Re: selinux.... again

2020-03-05 Thread Ed Greshko
On 2020-03-05 21:02, François Patte wrote: > Le 05/03/2020 à 13:53, Ed Greshko a écrit : >> When the server fails to start with selinux enabled what do you get with >> >> ausearch -m AVC,USER_AVC -ts recent >> > [root@dipankar ~]# ausearch -m AVC,USER_AVC -ts recent It is "odd" that you are gettin

Re: selinux.... again

2020-03-05 Thread François Patte
Le 05/03/2020 à 13:53, Ed Greshko a écrit : > On 2020-03-05 19:12, François Patte wrote: >> Bonjour, >> >> I am wondering why selinux changes its policy. I did note update or >> upgrade my system for a long time now, but selinux policy has changed! >> >> I used to use dictd server on my computer an

Re: selinux.... again

2020-03-05 Thread Ed Greshko
On 2020-03-05 19:12, François Patte wrote: > Bonjour, > > I am wondering why selinux changes its policy. I did note update or > upgrade my system for a long time now, but selinux policy has changed! > > I used to use dictd server on my computer and it worked fine up today: I > can't start the serve

selinux.... again

2020-03-05 Thread François Patte
Bonjour, I am wondering why selinux changes its policy. I did note update or upgrade my system for a long time now, but selinux policy has changed! I used to use dictd server on my computer and it worked fine up today: I can't start the server for selinux block it (If I setenforce 0, I can start

Re: SElinux (again)

2010-12-04 Thread Jorge Fábregas
On Saturday 04 December 2010 23:09:24 Jeffrey Ross wrote: > Ok so what do I need to tell SElinux to make it work again? Also where > do I find the logs for what SElinux is doing? or at least temporarily > enable logging? Check /var/log/messages for any SELinux message there. Also try this: s

Re: SElinux (again)

2010-12-04 Thread Jeffrey Ross
On 12/04/2010 10:09 PM, Jeffrey Ross wrote: > I'm running into a problem again with SElinux, I've put SElinux into > permissive mode and its working again. > > Using exim for the mailer and pgsql for the domain/username etc I get a > permission denied when exim attempts to access postgres, the actu

SElinux (again)

2010-12-04 Thread Jeffrey Ross
I'm running into a problem again with SElinux, I've put SElinux into permissive mode and its working again. Using exim for the mailer and pgsql for the domain/username etc I get a permission denied when exim attempts to access postgres, the actual error message is "PGSQL connection failed: coul