Re: [CentOS] EL8: SElinux / dac_override / tmpwatch

2020-08-29 Thread Leon Fauster via CentOS
Am 29.08.20 um 01:56 schrieb Jonathan Billings: On Aug 28, 2020, at 17:53, Leon Fauster via CentOS wrote: Is cron running in EL8 with stripped CAPs of? Does some one have an idea to address this? In general, we no longer use tmpwatch at all. In CentOS 7 and 8, use systemd-tmpfiles. Here

Re: [CentOS] EL8: SElinux / dac_override / tmpwatch

2020-08-28 Thread Jonathan Billings
On Aug 28, 2020, at 17:53, Leon Fauster via CentOS wrote: > > Is cron running in EL8 with stripped CAPs of? Does some one have an > idea to address this? In general, we no longer use tmpwatch at all. In CentOS 7 and 8, use systemd-tmpfiles. Here is a blog post that describes it pretty well:

[CentOS] EL8: SElinux / dac_override / tmpwatch

2020-08-28 Thread Leon Fauster via CentOS
Hi, I'm moving some old stuff from EL6 to EL8 and one setup has a cron job which uses "tmpwatch -umc $dir" to clean some directories (/etc/cron.daily/tmpwatch). It seems that this triggers this AVC (SElinux mode is enforcing): type=AVC msg=audit(1598576896.772:4267): avc: denied { dac_override