Neale Ferguson píše v Út 01. 02. 2011 v 15:02 -0600:
> I am playing with some snmpd stuff and on my Fedora 14 system I have
> the daemon up and running and want it to load a shared object. Without
> selinux it works but with it I get the following messages in the audit
> log file:
>
> type=AVC msg=audit(1296592954.939:1511): avc: denied { read } for
> pid=14084 comm="snmpd" name="dynamo.so" dev=dm-3 ino=45864
> scontext=unconfined_u:system_r:snmpd_t:s0
> tcontext=unconfined_u:object_r:admin_home_t:s0 tclass=file
> type=SYSCALL msg=audit(1296592954.939:1511): arch=80000016 syscall=5
> per=400000 success=no exit=-13 a0=2aaaaccf290 a1=0 a2=20000028a88 a3=0
> items=0 ppid=1 pid=14084 auid=503 uid=0 gid=0 euid=0 suid=0 fsuid=0
> egid=0 sgid=0 fsgid=0 tty=(none) ses=183 comm="snmpd"
> exe="/usr/sbin/snmpd" subj=unconfined_u:system_r:snmpd_t:s0 key=(null)
>
> What do I need to do to that file and/or to selinux to set the context
> correctly so that the process can read/load the file?
you need this
http://docs.fedoraproject.org/en-US/Fedora/13/html/Security-Enhanced_Linux/sect-Security-Enhanced_Linux-Working_with_SELinux-SELinux_Contexts_Labeling_Files.html
and for the right value of the context I would check other files from
the net-snmp package and/or the selinux policy sources
Dan
----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390
----------------------------------------------------------------------
For more information on Linux on System z, visit
http://wiki.linuxvm.org/