Re: ssh by user amandabackup

2011-01-03 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/02/2011 11:43 AM, Matthew Saltzman wrote: > On Sun, 2011-01-02 at 10:09 +0100, François Patte wrote: > Le 02/01/2011 02:14, Matthew Saltzman a crit : I'm trying to set up amanda using the amaddclient command. That requires that user a

Re: ssh by user amandabackup [SOLVED]

2011-01-04 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/04/2011 04:08 AM, Gordon Messmer wrote: > On 01/02/2011 06:45 AM, Matthew Saltzman wrote: >> Aha! In /var/log/messages, on the other hand, this happens: >> >> Jan 2 09:40:36 yankee setroubleshoot: SELinux is preventing >> /usr/sbin/ssh

Re: ssh by user amandabackup [SOLVED]

2011-01-04 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/04/2011 11:33 AM, Matthew Saltzman wrote: > On Tue, 2011-01-04 at 09:11 -0500, Daniel J Walsh wrote: >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> >> On 01/04/2011 04:08 AM, Gordon Messmer wrote: >>

Re: ssh by user amandabackup [SOLVED]

2011-01-04 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/04/2011 11:54 AM, Matthew Saltzman wrote: > On Tue, 2011-01-04 at 11:45 -0500, Daniel J Walsh wrote: >> You would need the combination of relabeling the homedir and searching >> /var/lib/amanda. >> >> WHich is what

Re: SELinux

2011-01-20 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/20/2011 11:43 AM, Bruno Wolff III wrote: > On Thu, Jan 20, 2011 at 17:52:37 +0200, > Kostas Sfakiotakis wrote: >> >> Well the thing is that i wanted to read a manual in pdf format . You see >> there are a lot of them hanging around . So what d

Re: SELinux

2011-01-20 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/20/2011 03:59 PM, Genes MailLists wrote: > On 01/20/2011 02:07 PM, Daniel J Walsh wrote: > >>> Using evince would be an improvement, but I wouldn't trust it to read PDFs >>> that I thought had a significant chance

Re: SELinux

2011-01-20 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/20/2011 04:17 PM, Kostas Sfakiotakis wrote: > < snip > > >>> Using evince would be an improvement, but I wouldn't trust it to >>> read PDFs that I thought had a significant chance of being >>> trojans. >> sandbox -X evince random.pdf >> >> On

Re: SELinux

2011-01-21 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/20/2011 05:12 PM, Jorge Fábregas wrote: > On 01/20/2011 05:23 PM, Daniel J Walsh wrote: >> yum install policycoreutils-sandbox > > Shouldn't this package be a dependency of the package > policycoreutils-p

Re: SELinux

2011-01-21 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/20/2011 05:12 PM, Genes MailLists wrote: > On 01/20/2011 05:02 PM, Genes MailLists wrote: >> On 01/20/2011 04:23 PM, Daniel J Walsh wrote: >> >> >> If I want to run google chrome (say)- >> >> I tri

Re: SELinux

2011-01-21 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/21/2011 08:31 AM, John Austin wrote: > On Fri, 2011-01-21 at 07:42 -0500, Daniel J Walsh wrote: > On 01/20/2011 05:12 PM, Genes MailLists wrote: >>>> On 01/20/2011 05:02 PM, Genes MailLists wrote: >>>>> On 01

Re: SELinux

2011-01-21 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/21/2011 09:12 AM, John Austin wrote: > On Fri, 2011-01-21 at 08:49 -0500, Daniel J Walsh wrote: >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> >> On 01/21/2011 08:31 AM, John Austin wrote: >>> On Fri,

Re: SELinux

2011-01-21 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/21/2011 09:28 AM, Genes MailLists wrote: > On 01/21/2011 07:42 AM, Daniel J Walsh wrote: > >> Lets figure out if this is a chromium problem or something else. Does >> >> sandbox -X xterm >> >> Work? > &g

Re: SELinux

2011-01-21 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/21/2011 10:12 AM, Genes MailLists wrote: > On 01/21/2011 09:35 AM, Daniel J Walsh wrote: > : >> >>> % sandbox -X -H /home/gene/sandbox/home /opt/google/chrome/chrome >> >>> /opt/google/chrome/chrome:

Re: SELinux

2011-01-21 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/21/2011 11:20 AM, Genes MailLists wrote: > On 01/21/2011 11:07 AM, Daniel J Walsh wrote: >> sandbox -X -W metacity -t sandbox_web_t -H ~/sandbox/home >> /opt/google/chrome/chrome > > Same thing - window starts and cl

Re: SELinux

2011-01-21 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/21/2011 11:43 AM, Genes MailLists wrote: > On 01/21/2011 11:31 AM, Daniel J Walsh wrote: > . >> >> I think it has something about namespaces. >> If you run >> >> sandbox -X -t sandbox_web_t xterm >> &

Re: Setroubleshoot errors in /var/log/messages

2011-01-24 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/22/2011 06:34 PM, Richard Shaw wrote: > 2011/1/22 Jorge Fábregas : >> On 01/22/2011 11:02 AM, Richard Shaw wrote: >>> Jan 22 08:59:45 hobbes setroubleshoot: Setroubleshoot can not analyze >>> AVCs while dontaudit rules are disabled, 'semodule -B'

Desktop effects disable problem

2011-01-24 Thread Daniel J. Celta
accept any upgrades to any of the available releases. Also I have read some threads where they recommend renaming the .kde directory but no luck, the problem still remains. Any help would be greatly appreciated -- Daniel J Celta Main: 713 487 9307 email: dce...@gmail.com -- users mailing list

Desktop effects disable problem

2011-01-25 Thread Daniel J. Celta
Aaron thanks for the reply. On Mon, 2011-01-24 at 22:06 -0600, Daniel J. Celta wrote: > Guys I need help > > By mistake I activate the desktop effects and now all I can see is a > blank screen and the mouse, I reboot and nothing I get back to the > blank screen. > What deskto

Re: Desktop effects disable problem

2011-01-25 Thread Daniel J. Celta
roject.org > To unsubscribe or change subscription options: > https://admin.fedoraproject.org/mailman/listinfo/users > Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines > -- Daniel J Celta -- users mailing list users@lists.fedoraproject.org To unsubscribe or cha

Re: Desktop effects disable problem

2011-01-25 Thread Daniel J. Celta
> I've had to do this on occasion (with compiz-gnome). > > > - Mike > -- > users mailing list > users@lists.fedoraproject.org > To unsubscribe or change subscription options: > https://admin.fedoraproject.org/mailman/listinfo/users > Guidelines: http://fedoraprojec

Re: Desktop effects disable problem

2011-01-25 Thread Daniel J. Celta
No, I lost the ability to display and switch between workspaces. ? If I reinstall the compiz-gnome the problem comes back.. On Tue, Jan 25, 2011 at 11:51, Dr. Michael J. Chudobiak wrote: > On 01/25/2011 12:44 PM, Daniel J. Celta wrote: >> >> Running the "yum

Re: Desktop effects disable problem

2011-01-25 Thread Daniel J. Celta
the computer reverts back to a blank screen.. Is there a way to revert back, and/or removing the setting "desktop-effects", back to the default. On Tue, Jan 25, 2011 at 12:02, Dr. Michael J. Chudobiak wrote: > On 01/25/2011 12:56 PM, Daniel J. Celta wrote: >> No, I

Re: Desktop effects disable problem

2011-01-25 Thread Daniel J. Celta
Wait a minute. What did that command do??? On Tue, Jan 25, 2011 at 12:29, Dr. Michael J. Chudobiak wrote: > Daniel J. Celta wrote: >> Now after removing compiz-gnome, now the windows manager is not >> working properly.  All the windows get anchored to the upper left >>

Re: Desktop effects disable problem

2011-01-25 Thread Daniel J. Celta
install compiz-gnome" the blank screen comes back... Is there a way to revert this desktop effects setting On Tue, Jan 25, 2011 at 15:35, Aaron Konstam wrote: > On Tue, 2011-01-25 at 10:27 -0600, Daniel J. Celta wrote: >> Aaron thanks for the reply. >> >> On Mo

Re: Can't permanently disable SELinux warning for Wine.

2011-01-26 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/25/2011 09:10 PM, Jorge Fábregas wrote: > On 01/25/2011 10:03 PM, Linuxguy123 wrote: >> That is all well and good, but when I issue the command (as root), it >> hangs. Only Ctrl C will terminate the command. >> >> However, if I omit the "-P", it

Re: Selinux warning -

2010-01-13 Thread Daniel J Walsh
On 01/13/2010 12:43 PM, Bob Goodwin wrote: > I'm not sure what this means or how to react to it. I noticed it for the > first time after an update a little while ago although it also refers to > an earlier episode. This is the first time I saw it though. > > Advise appreciated. > > Bob > > >

Re: Selinux warning -

2010-01-13 Thread Daniel J Walsh
On 01/13/2010 03:06 PM, Bob Goodwin wrote: > SELinux is preventing /usr/sbin/abrtd (deleted) "write" access on > /etc/abrt. https://bugzilla.redhat.com/show_bug.cgi?id=550523 THis is the open bug report. -- users mailing list users@lists.fedoraproject.org To unsubscribe: https://admin.fedor

Re: Pidgin problems with AIM?

2010-01-13 Thread Daniel B. Thurman
Sam Varshavchik wrote: > Anyone else getting the following error when trying to sign in to AIM, > today: > > "Received unexpected response from > http://api.oscar.aol.com/aim/startOSCARSession"; > > Yes, I found that disabling SSL works. They have a problem with the SSL connections apparently.

Re: need howto for SELinux config--ssh on non-standard port

2010-01-14 Thread Daniel J Walsh
On 01/13/2010 10:48 PM, John Poelstra wrote: > Ed Greshko said the following on 01/13/2010 06:32 PM Pacific Time: >> John Poelstra wrote: >>> [r...@localhost ~]# grep ssh /var/log/audit/audit.log | audit2allow -m myssh >>> Traceback (most recent call last): >>> File "/usr/bin/audit2allow", line

Re: need howto for SELinux config--ssh on non-standard port

2010-01-14 Thread Daniel J Walsh
On 01/14/2010 10:33 AM, Paul W. Frields wrote: > On Wed, Jan 13, 2010 at 07:48:24PM -0800, John Poelstra wrote: >> Ed Greshko said the following on 01/13/2010 06:32 PM Pacific Time: >>> John Poelstra wrote: [r...@localhost ~]# grep ssh /var/log/audit/audit.log | audit2allow -m myssh

Re: need howto for SELinux config--ssh on non-standard port

2010-01-20 Thread Daniel J Walsh
On 01/19/2010 05:28 PM, John Poelstra wrote: > Daniel J Walsh said the following on 01/07/2010 05:23 AM Pacific Time: >> On 01/06/2010 09:29 PM, John Poelstra wrote: >>> I'm running sshd on a high (>1024) port number and cannot find a clear >>> step by step guid

Re: Fedora 12 update causing SELinux alerts [SOLVED]

2010-01-20 Thread Daniel J Walsh
On 01/20/2010 04:49 PM, Roger wrote: > On 01/21/2010 12:12 AM, n2xssvv.g02gfr12930 wrote: >> On 01/20/2010 10:15 AM, n2xssvv.g02gfr12930 wrote: >> >>> After upgrading from Fedora 11 to 12 I now receive the following SELinux >>> alerts >>> >>> SELinux is preventing /sbin/setfiles "read" access o

Re: Fedora 12 update causing SELinux alerts [REAPPEARED]

2010-01-21 Thread Daniel J Walsh
On 01/21/2010 07:42 AM, n2xssvv.g02gfr12930 wrote: > On 01/20/2010 01:12 PM, n2xssvv.g02gfr12930 wrote: >> On 01/20/2010 10:15 AM, n2xssvv.g02gfr12930 wrote: >>> >>> After upgrading from Fedora 11 to 12 I now receive the following SELinux >>> alerts >>> >>> SELinux is preventing /sbin/setfiles "rea

Re: need howto for SELinux config--ssh on non-standard port

2010-01-21 Thread Daniel J Walsh
On 01/20/2010 11:35 PM, John Poelstra wrote: > Daniel J Walsh said the following on 01/20/2010 11:26 AM Pacific Time: >> On 01/19/2010 05:28 PM, John Poelstra wrote: >>> Daniel J Walsh said the following on 01/07/2010 05:23 AM Pacific Time: >>>> On 01/06/2010

Help: Where is the subscriber's account manager?

2010-01-23 Thread Daniel B. Thurman
I need access to my account and the old redhat site is no longer valid! Where is the link to manage the subscribers account, please? Thanks! Dan -- users mailing list users@lists.fedoraproject.org To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/users Guidelines: http://fedorapro

Need subscriber's account link

2010-01-23 Thread Daniel B. Thurman
The old redhat subscriber's account manager is no long valid and I need the the new link, please? Thanks- Dan -- users mailing list users@lists.fedoraproject.org To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/users Guidelines: http://fedoraproject.org/wiki/Communicate/MailingL

Where is the link for subscriber's account?

2010-01-25 Thread Daniel B. Thurman
I need to change my account settings but unable to find the link as my old redhat link is no longer valid? Thanks! Dan -- users mailing list users@lists.fedoraproject.org To unsubscribe or change subscription options: https://admin.fedoraproject.org/mailman/listinfo/users Guidelines: http://fedo

Re: need howto for SELinux config--ssh on non-standard port

2010-01-25 Thread Daniel J Walsh
On 01/24/2010 11:11 PM, John Poelstra wrote: > Daniel J Walsh said the following on 01/21/2010 05:05 AM Pacific Time: >> On 01/20/2010 11:35 PM, John Poelstra wrote: >>> >>> Where else should I be looking? >>> >>> It is very clear that I can log in rem

F11 Issues

2010-02-02 Thread Daniel B. Thurman
Updates: libmrpt-hwdrivers.so.0.7 is needed by package mrpt-monoslam-0.7.1-0.1.20090818svn1148.fc11.i586 libmrpt-core.so.0.7 is needed by package mrpt-monoslam-0.7.1-0.1.20090818svn1148.fc11.i586 libprojectM.so.2 is needed by package ultrastardx-1.1.1-1.7.20090411.fc11.i586 + This has been around

Re: F11 Issues

2010-02-02 Thread Daniel B. Thurman
On 02/02/2010 12:58 PM, Sam Sharpe wrote: > On 2 February 2010 20:32, Daniel B. Thurman wrote: > > >> libprojectM.so.2 is needed by package >> ultrastardx-1.1.1-1.7.20090411.fc11.i586 >> > http://fr2.rpmfind.net/linux/RPM/rpmfusion/free/fedora/11/x86_64/ultra

Re: latest selinux policy update errors

2010-02-03 Thread Daniel J Walsh
Mark Haney wrote: > Is anyone else seeing these types of failures with the latest selinux > updates? > > libsemanage.semanage_direct_remove: Module dpkg was not found. > semodule: Failed on dpkg! > error: %trigger(selinux-policy-strict-2.6.4-21.fc7.noarch) scriptlet > failed, exit status 1 > libse

Re: SELinux detecting suspicious behavior on my system

2010-02-04 Thread Daniel J Walsh
On 02/04/2010 01:50 PM, Kevin Kempter wrote: > Hi All; > > I've seen several of the below SELinux messages recently, I do have root > logins disables in my /etc/ssh/sshd_config file: > > > PermitRootLogin no > > > > > Any thoughts on this? Is it cause for concern? > > > > > ===

Re: selinux=0

2013-12-31 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/29/2013 10:31 AM, Patrick Dupre wrote: > > Thank, It works. > >> >> On Sun, 29 Dec 2013 14:40:26 +0100, Patrick Dupre wrote: >> >>> Hello, >>> >>> After cloning a distribution fedora 19, I have to set selinux=0 to be >>> able to boot. How ca

Re: failed to ..

2013-12-31 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/30/2013 11:11 AM, Chris Murphy wrote: > > On Dec 29, 2013, at 11:37 PM, Ralf Corsepius wrote: > >> On 12/30/2013 07:01 AM, Chris Murphy wrote: >>> >>> On Dec 28, 2013, at 8:15 PM, Patrick Dupre wrote: >>> Hello, I tried to s

Re: failed to ..

2014-01-02 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/31/2013 12:20 PM, Chris Murphy wrote: > > On Dec 31, 2013, at 8:57 AM, Daniel J Walsh wrote: > >> THere was a bug in libselinux which is now fixed, that was causing the >> problem. > > Right, but I thought that th

Re: fedup and selinux

2014-01-02 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I blogged on SELinux blocking stuff in permissive mode. http://danwalsh.livejournal.com/67855.html I think fedup putting the machine into permissive mode during the update is the sane thing to do, and since it should be doing this without services ru

Re: Why did SELinux relable my filesystem?

2014-01-02 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/25/2013 06:25 AM, Steven P. Ulrick wrote: > Hello, Everyone During my most recent re-boot, SELinux relabled my entire > filesystem. Which would be fine, except for the fact that I have SELinux > disabled on my system: > >> # This file controls t

Re: Different actions on different passwords?

2014-01-02 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/30/2013 08:09 PM, Robert Moskowitz wrote: > > On 12/30/2013 08:03 PM, Bill Oliver wrote: >> On Tue, 31 Dec 2013, Patrick O'Callaghan wrote: >> >>> >>> On Mon, Dec 30, 2013 at 11:25 PM, Bill Oliver >>> wrote: >>> >>> In linux, is it possible

Re: Trying to use mailx for logwatch

2014-01-03 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/02/2014 05:29 PM, Robert Moskowitz wrote: > And the mail is failing. Here is what I have done: > > I determined that in: /usr/share/logwatch/default.conf/logwatch.conf mailer > = "/usr/sbin/sendmail -t" > > so in: /etc/logwatch/conf/logwatch.c

Re: Trying to use mailx for logwatch

2014-01-03 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/03/2014 11:34 AM, Robert Moskowitz wrote: > > On 01/03/2014 11:21 AM, Daniel J Walsh wrote: >> -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 >> >> On 01/02/2014 05:29 PM, Robert Moskowitz wrote: >>> And the

Re: GCL get killed everytime I try to execute it

2014-01-06 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/05/2014 09:21 PM, Rex Dieter wrote: > Isaac Cortés González wrote: > >> Ok here's my problem: I'm trying to learn (Common) Lisp, so I installed >> GCL, to compile or run the scripts that I'm making for practice; but I'm >> having problems to r

Re: Trying to use mailx for logwatch

2014-01-06 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/03/2014 12:25 PM, Robert Moskowitz wrote: > > On 01/03/2014 12:03 PM, Daniel J Walsh wrote: >> -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 >> >> On 01/03/2014 11:34 AM, Robert Moskowitz wrote: >>> On 01/03/20

Re: Trying to use mailx for logwatch

2014-01-07 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/07/2014 11:44 AM, Robert Moskowitz wrote: > getting closer. I am running a new install. So a fresh start on this... > > On 01/06/2014 11:14 AM, Daniel J Walsh wrote: >> -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 >> &

Re: update partially fails

2014-01-20 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/18/2014 12:15 PM, antonio montagnani wrote: > Patrick Dupre ha scritto / said the followingil giorno/on 18/01/2014 > 17:59: >> Hello, >> >> The last update did not go very well. I got: Failed: bind.i686 >> 32:9.9.4-8.fc20 bind.i686 32:9.9.4-

Re: logwatch error messages

2014-01-23 Thread Daniel J Walsh
uid=0 egid=0 sgid=0 fsgid=0 > ses=16 tty=(none) comm="logwatch" exe="/usr/bin/perl" > subj=system_u:system_r:logwatch_t:s0-s0:c0.c1023 key=(null) Jan 22 03:37:14 > lx120e.htt-consult.com setroubleshoot[11102]: analyze_avc() > avc=scontext=system_u:system_r:logwatch_t:s0-s0:c0.

Re: logwatch error messages

2014-01-23 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/23/2014 01:54 PM, Robert Moskowitz wrote: > > On 01/23/2014 08:38 AM, Daniel J Walsh wrote: >> -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 >> >> On 01/22/2014 11:07 PM, Robert Moskowitz wrote: >>> I a

Re: policycoreutils packaging bug?

2014-02-17 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/17/2014 10:14 AM, Jon Ingason wrote: > 2014-02-17 15:56, Suvayu Ali skrev: >> install policycoreutils-sandbox > I have two machines, both x86_64. On does have > policycoreutils-sandbox-2.2.5-3.fc20.x86_64 installed while the other > don't. > >

Re: google-chrome not displaying text with selinux enforcing

2014-02-26 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/26/2014 02:00 PM, Dale Dellutri wrote: > I've got a Fedora 20 XFCE desktop. I installed google-chrome. It fails to > display some text on many web sites if selinux is set to enforcing, but > shows the text with selinux set to permissive. > > Fo

Re: google-chrome not displaying text with selinux enforcing

2014-02-27 Thread Daniel J Walsh
blem occurred because I added a >> directory of private fonts to /usr/share/fonts/, but I did not adjust >> the selinux context for that directory. The ausearch suggested by Daniel >> Walsh discovered the problem. >> >> I really must learn more about the care and feedin

Re: after upgrading fedora rawhide this morning, no graphical desktop

2014-03-14 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/13/2014 02:58 PM, Robert P. J. Day wrote: > On Thu, 13 Mar 2014, Kevin Martin wrote: > >> On 03/13/2014 07:57 AM, Robert P. J. Day wrote: >>> >>> recently, i upgraded my ASUS G74S laptop to fedora rawhide and it was >>> running nicely. then thi

Re: new SELinux error

2014-03-27 Thread Daniel J Walsh
What was the AVC that you got? On 03/27/2014 04:58 PM, Paul Cartwright wrote: > I am not sure what to do.. > > I got this error message: > # semanage fcontext -a -t FILE_TYPE '$FIX_TARGET_PATH' > where FILE_TYPE is one of the following: NetworkManager_log_t, > NetworkManager_tmp_t, abrt_helper_exec

Re: new SELinux error

2014-03-28 Thread Daniel J Walsh
ausearch -m avc,user_avc -i Or just attach the full output of the sealert command. The AVC's are at the bottom. -- users mailing list users@lists.fedoraproject.org To unsubscribe or change subscription options: https://admin.fedoraproject.org/mailman/listinfo/users Fedora Code of Conduct: http:

Re: fedup 19=>20 hangs: selinux

2014-04-08 Thread Daniel J Walsh
This usually means there is no /etc/selinux/targeted/policy/policy.* file. If you run semodule -B Does one get created? On 04/08/2014 10:59 AM, Sean Darcy wrote: > Trying to upgrade F19 to F20 using fedup. On the upgrade reboot it hangs: > > > Reached target Initrd Default Target > s

Re: fedup 19=>20 hangs: selinux

2014-04-09 Thread Daniel J Walsh
So this looks like selinux-policy-targeted got removed during the update? On 04/09/2014 04:21 PM, Sean Darcy wrote: > On 04/08/2014 11:54 AM, Daniel J Walsh wrote: >> This usually means there is no /etc/selinux/targeted/policy/policy.* >> file. >> >> If you run semodu

Re: fedup 19=>20 hangs: selinux

2014-04-10 Thread Daniel J Walsh
Strange, if selinux-policy-targeted is not installed SELinux is disabled. On 04/09/2014 08:31 PM, Sean Darcy wrote: > On 04/09/2014 06:01 PM, Daniel J Walsh wrote: >> So this looks like selinux-policy-targeted got removed during the >> update? >> >> On 04/09/2014

Re: Two SELinux-related things

2014-04-25 Thread Daniel J Walsh
On 04/24/2014 04:56 PM, Mark Brader wrote: >> # semanage fcontext -a -e /home /u >> # restorecon -R -v /u >> >> Should fix you up. > Bingo. Thanks for your time. > > I did wonder if this was the cause of the problem, but (1) it didn't happen > with the previous Linux configuration I had, and (2)

Re: Trouble starting webex in F20

2014-05-02 Thread Daniel J Walsh
On 05/01/2014 06:26 PM, Chris Kottaridis wrote: > > On 05/01/2014 05:08 PM, Rick Stevens wrote: >> On 05/01/2014 01:40 PM, Andrew Azores issued this missive: >>> On 05/01/2014 04:27 PM, Chris Kottaridis wrote: On 05/01/2014 02:11 PM, Deepak Bhole wrote: > * Chris Kottaridis [2014-05

Re: Trouble starting webex in F20

2014-05-02 Thread Daniel J Walsh
On 05/02/2014 01:19 PM, Chris Kottaridis wrote: > > On 05/02/2014 12:07 PM, Daniel J Walsh wrote: >> >> On 05/01/2014 06:26 PM, Chris Kottaridis wrote: >>> >>> On 05/01/2014 05:08 PM, Rick Stevens wrote: >>>> On 05/01/2014 01:40 PM, Andrew Azores i

Re: cups-pdf

2014-05-05 Thread Daniel J Walsh
On 05/04/2014 06:27 PM, Patrick Dupre wrote: > >> - Original Message - >> From: Steven Stern >> Sent: 05/05/14 12:03 AM >> To: Community support for Fedora users >> Subject: Re: cups-pdf >> >> On 05/04/2014 04:57 PM, Patrick Dupre wrote: >>> - Original Message - From: Ste

Re: Set SELinux to allow only httpd daemon to use specific tty device

2014-05-05 Thread Daniel J Walsh
On 05/04/2014 12:22 AM, Emmanuel Noobadmin wrote: > Using Fedora 20 3.11.10-301.fc20.x86_64 and selinux targeted policy.29 > > I've a PHP application that sends data to a USB tty device e.g. > /dev/usbDataCollector > > Unfortunately selinux is blocking this action. When set to permissive, > the al

Re: Set SELinux to allow only httpd daemon to use specific tty device

2014-05-06 Thread Daniel J Walsh
On 05/06/2014 12:03 AM, Emmanuel Noobadmin wrote: > On 5/5/14, Daniel J Walsh wrote: >> Simplest would be to just use >> # grep usbDataCollector /var/log/audit/audit.log | audit2allow -M myhttp >> # semodule -i myhttp.pp >> >> This would allot httpd_t processe

Re: Problem with selinux and milter-greylist

2014-05-27 Thread Daniel J Walsh
On 05/27/2014 12:55 PM, arag...@dcsnow.com wrote: > > Hi, > > So I'm trying to get milter-greylist working with > selinux > and I seem to have a problem. It doesn't seem to know > what > milter-greylist is trying to access so I can't add a rule to fix > it. > Here is what I see in /var/log/mes

Re: Problem with selinux and milter-greylist

2014-05-27 Thread Daniel J Walsh
On 05/27/2014 01:35 PM, arag...@dcsnow.com wrote: > > Looks like the milter-greylist.sock is mislabeled. What directory is it > > in? Why isn't it in /run? > > Well, see, I was following a guide (probably old) that pointed > Sendmail to /var/milter-greylist so I just changed the greylist.conf > fi

Re: Wifi connection issues with Intel?

2014-06-12 Thread Daniel J Walsh
On 06/11/2014 01:48 PM, Richard Shaw wrote: > On Wed, Jun 11, 2014 at 3:31 PM, poma > wrote: > > There are four "indoor" models, and basic one ain't 5 GHz. > > > Yes, I have the basic one, so it does support "n" but in 2.4GHz only. > > > > Besides the

Re: google-chrome + selinux + ecryptfs

2014-06-12 Thread Daniel J Walsh
How is ecryptfs supposed to work? On 06/12/2014 03:13 PM, Pal, Laszlo wrote: > node= type=SYSCALL msg=audit(1402610675.802:3612): arch=c03e > syscall=47 success=yes exit=1 a0=12 a1=7f4cb29bb490 a2=40 a3=2 items=0 > ppid=8 pid=13635 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000 > fsuid=1000 e

Re: Wifi connection issues with Intel?

2014-06-16 Thread Daniel J Walsh
On 06/12/2014 10:14 AM, Richard Shaw wrote: > On Thu, Jun 12, 2014 at 6:56 AM, Daniel J Walsh <mailto:dwa...@redhat.com>> wrote: > >> The full unifi software is java with a mongodb database backend >> and works fine. I have a RPM I created, the only problem I

Re: Wifi connection issues with Intel?

2014-06-16 Thread Daniel J Walsh
On 06/16/2014 01:35 PM, Richard Shaw wrote: > On Mon, Jun 16, 2014 at 12:19 PM, Daniel J Walsh <mailto:dwa...@redhat.com>> wrote: > > > On 06/12/2014 10:14 AM, Richard Shaw wrote: >> On Thu, Jun 12, 2014 at 6:56 AM, Daniel J Walsh >>

Re: Selinux Packaging [WAS: Wifi connection issues with Intel?]

2014-06-16 Thread Daniel J Walsh
On 06/16/2014 02:15 PM, Richard Shaw wrote: > On Mon, Jun 16, 2014 at 1:08 PM, Daniel J Walsh <mailto:dwa...@redhat.com>> wrote: > > > On 06/16/2014 01:35 PM, Richard Shaw wrote: >> On Mon, Jun 16, 2014 at 12:19 PM, Daniel J Walsh >>

Re: fedora-dockerfiles: "LABEL" lines in cockpit-ws sample file look weird

2015-08-10 Thread Daniel J Walsh
On 08/10/2015 05:43 AM, Robert P. J. Day wrote: > brief digression from my discussion of docker roadmap and stuff like > that ... i'm using the sample Dockerfiles from the > "fedora-dockerfiles" package to demonstrate various Dockerfile > instructions in an upcoming course, and i ran across thi

Re: fedora-dockerfiles: "LABEL" lines in cockpit-ws sample file look weird

2015-08-10 Thread Daniel J Walsh
On 08/10/2015 08:31 AM, Robert P. J. Day wrote: > On Mon, 10 Aug 2015, Daniel J Walsh wrote: > >> >> On 08/10/2015 05:43 AM, Robert P. J. Day wrote: >>> brief digression from my discussion of docker roadmap and stuff like >>> that ... i'm using th

Re: fedora-dockerfiles: "LABEL" lines in cockpit-ws sample file look weird

2015-08-10 Thread Daniel J Walsh
/10/2015 08:43 AM, Daniel J Walsh wrote: > > On 08/10/2015 08:31 AM, Robert P. J. Day wrote: >> On Mon, 10 Aug 2015, Daniel J Walsh wrote: >> >>> On 08/10/2015 05:43 AM, Robert P. J. Day wrote: >>>> brief digression from my discussion of docker roadmap and

Re: fedora-dockerfiles: "LABEL" lines in cockpit-ws sample file look weird

2015-08-10 Thread Daniel J Walsh
, Robert P. J. Day wrote: > On Mon, 10 Aug 2015, Daniel J Walsh wrote: > >> Here are a couple of blogs on the atomic command >> >> http://developerblog.redhat.com/2015/04/21/introducing-the-atomic-command/ >> http://www.projectatomic.io/blog/2015/04/using-environmen

Re: current/proposed docker-related packages?

2015-08-17 Thread Daniel J Walsh
On 08/16/2015 05:04 AM, Robert P. J. Day wrote: > On Sat, 15 Aug 2015, Kenneth Wolcott wrote: > >> I have a related question about Fedora docker packages. There seems >> to be a docker-engine at version 1.8.1 and docker at version 1.7.1. >> I'd like to have docker AND docker engine at the same v

Re: current/proposed docker-related packages?

2015-08-17 Thread Daniel J Walsh
On 08/17/2015 08:06 AM, Daniel J Walsh wrote: > > On 08/16/2015 05:04 AM, Robert P. J. Day wrote: >> On Sat, 15 Aug 2015, Kenneth Wolcott wrote: >> >>> I have a related question about Fedora docker packages. There seems >>> to be a docker-engine at versi

Re: doing docker build, "SELinux is preventing /usr/libexec/abrt-hook-ccpp from using the sigchld access on a process.", kills wireless

2015-08-19 Thread Daniel J Walsh
On 08/19/2015 02:43 AM, Robert P. J. Day wrote: > On Tue, 18 Aug 2015, Robert P. J. Day wrote: > >> by now, i'm getting *really* good at debugging. was doing a simple >> docker build (docker-1.8.1) with first few lines of Dockerfile (which >> worked fine not that long ago): >> >> FROM ubuntu:

Re: doing docker build, "SELinux is preventing /usr/libexec/abrt-hook-ccpp from using the sigchld access on a process.", kills wireless

2015-08-19 Thread Daniel J Walsh
On 08/19/2015 07:36 AM, Robert P. J. Day wrote: > On Wed, 19 Aug 2015, Daniel J Walsh wrote: > >> On 08/19/2015 02:43 AM, Robert P. J. Day wrote: >>> On Tue, 18 Aug 2015, Robert P. J. Day wrote: >>> >>>> by now, i'm getting *really* good at

Re: doing docker build, "SELinux is preventing /usr/libexec/abrt-hook-ccpp from using the sigchld access on a process.", kills wireless

2015-08-19 Thread Daniel J Walsh
On 08/19/2015 08:03 AM, Robert P. J. Day wrote: > On Wed, 19 Aug 2015, Daniel J Walsh wrote: > >> With SELinux disabled you should not be getting any AVC's >> >> If you turn SELInux back on and do a full relabel, I think the problem >> will go away. >>

Re: doing docker build, "SELinux is preventing /usr/libexec/abrt-hook-ccpp from using the sigchld access on a process.", kills wireless

2015-08-20 Thread Daniel J Walsh
: > On Wed, 19 Aug 2015, Rick Stevens wrote: > >> On 08/19/2015 08:41 AM, Robert P. J. Day wrote: >>> On Wed, 19 Aug 2015, Daniel J Walsh wrote: >>> >>>> >>>> On 08/19/2015 07:36 AM, Robert P. J. Day wrote: >>>>> On Wed, 19 Aug 2015, D

Re: AVC denial and the suggested actio to take (by the setroubleshoot details) window

2015-09-24 Thread Daniel J Walsh
What AVC are you seeing? On 09/24/2015 01:58 PM, jd1008 wrote: > After getting AVC denial, I touched /.autorelabel and rebooted. > Took about 5 minutes to finish re-labeling. > Then, I started to ge more AVC denials. > I clicked on the denial icon and read the details. > > Could someone please exp

Re: AVC denial and the suggested actio to take (by the setroubleshoot details) window

2015-09-24 Thread Daniel J Walsh
On 09/24/2015 03:15 PM, jd1008 wrote: > > > On 09/24/2015 12:58 PM, Daniel J Walsh wrote: >> What AVC are you seeing? >> >> On 09/24/2015 01:58 PM, jd1008 wrote: >>> After getting AVC denial, I touched /.autorelabel and rebooted. >>> Took about

Re: AVC denial and the suggested actio to take (by the setroubleshoot details) window

2015-09-25 Thread Daniel J Walsh
Why use symlinks versus bind mounts? Or mount the directory there directly. On 09/24/2015 07:20 PM, jd1008 wrote: > > > On 09/24/2015 04:54 PM, Rahul Sundaram wrote: >> Hi >> >> On Thu, Sep 24, 2015 at 4:20 PM, jd1008 wrote: >> >> But /home is a symlink to /home on another mount point. >>

Re: SElinux issue

2015-09-25 Thread Daniel J Walsh
Looks like you might have a prewikka policy around? locate prewikka.pp Did you build a custom policy module? On 09/25/2015 02:30 PM, Paolo Galtieri wrote: > Folks, > I got an SElinux alert this morning. The suggestion to correct the > problem was to do: > > setsebool -P unconfined_mozilla_pl

Re: AVC denial and the suggested actio to take (by the setroubleshoot details) window

2015-09-25 Thread Daniel J Walsh
On 09/25/2015 01:54 PM, jd1008 wrote: > > > On 09/25/2015 11:28 AM, Daniel J Walsh wrote: >> mount the directory there directly > You mean mount a partition as /home? > I do not have that. > Anyways where are your homedirs? -- users mailing list users@lists.fedoraproje

Re: AVC denial and the suggested actio to take (by the setroubleshoot details) window

2015-09-25 Thread Daniel J Walsh
On 09/25/2015 03:55 PM, jd1008 wrote: > > > On 09/25/2015 01:26 PM, Daniel J Walsh wrote: >> >> On 09/25/2015 01:54 PM, jd1008 wrote: >>> >>> On 09/25/2015 11:28 AM, Daniel J Walsh wrote: >>>> mount the directory there directly >>>

Re: SElinux issue

2015-09-29 Thread Daniel J Walsh
(*prew*ikka_script_t) prelude.te: postgresql_tcp_connect(*prew*ikka_script_t) semodule -l | grep prelude On 09/25/2015 06:51 PM, Paolo Galtieri wrote: > Daniel, > on the machine on which things work there is a prewikka.pp file, but > on the one that fails there isn&#

Re: Copying files without losing selinux context

2015-10-11 Thread Daniel J Walsh
On 10/10/2015 05:07 AM, Suvayu Ali wrote: > Hi Rejy, > > On Sat, Oct 10, 2015 at 12:31:59PM +0530, Rejy M Cyriac wrote: >> On 10/08/2015 06:35 PM, Suvayu Ali wrote: >>> Yesterday I installed a new SSD in my laptop. I moved all my files >>> (/home, /var, /opt) with rsync and rebooted. However I

Re: SELinux is preventing rsyslogd from getattr access on the file

2015-10-22 Thread Daniel J Walsh
Looks like it wants you to fix your labels on /var/log restorecon -R -v /var/log On 10/22/2015 11:00 AM, Neal Becker wrote: > Oct 22 10:59:22 nbecker2 setroubleshoot: Plugin Exception restorecon_source > Oct 22 10:59:22 nbecker2 setroubleshoot: SELinux is preventing rsyslogd from > getattr acce

Re: Discourse - DeviceMapper causing corruption?

2016-03-21 Thread Daniel J Walsh
Do we have bugzillas with these Spectacular failures? On 03/21/2016 03:03 PM, Philip Rhoades wrote: People, I had a couple of issues to sort out with installing the Docker Discourse app and while that was being done people made these comments: "Devicemapper is non starter, fails spectacularl

Re: PulseAudio

2016-03-25 Thread Daniel J Walsh
On 03/25/2016 09:20 AM, Richard Ibbotson wrote: Hi I know a lot of people don't like PulseAudio but that's what comes with Fedora 23. My problem is this. After a dnf update I find that selinux has done something it didn't do before. PulseAudio has ceased to work properly. I'm looking at a dumm

Re: PulseAudio

2016-03-28 Thread Daniel J Walsh
On 03/25/2016 12:49 PM, Joe Zeff wrote: On 03/25/2016 06:58 AM, Richard Ibbotson wrote: On Friday 25 March 2016 09:41:05 Daniel J Walsh wrote: What avcs are you seeing ausearch -m avc -ts recent Well, that just about proves that SELinux isn't involved, doesn't it? Well may

<    1   2   3   4   5   6   7   8   9   >