Thanks. I used the chcon command to change the context but am still having 
problems and seeing this in the audit log:

type=AVC msg=audit(1296596790.809:1547): avc:  denied  { execute } for  
pid=14580 comm="snmpd" path="/usr/lib64/snmp/dlmod/dynamo.so" dev=dm-3 
ino=45864 scontext=unconfined_u:system_r:snmpd_t:s0 
tcontext=unconfined_u:system_r:snmpd_t:s0 tclass=file
type=SYSCALL msg=audit(1296596790.809:1547): arch=80000016 syscall=90 
per=400000 success=no exit=-13 a0=3ffffb17160 a1=6650 a2=5 a3=802 items=0 
ppid=1 pid=14580 auid=503 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 
fsgid=0 tty=(none) ses=183 comm="snmpd" exe="/usr/sbin/snmpd" 
subj=unconfined_u:system_r:snmpd_t:s0 key=(null)

ls -RlZ /usr/lib64/snmp/
/usr/lib64/snmp/:
drwxr-xr-x. root root unconfined_u:system_r:snmpd_t:s0 dlmod

/usr/lib64/snmp/dlmod:
-rwxr-xr-x. root root unconfined_u:system_r:snmpd_t:s0 dynamo.so

I am probably being naïve in believing that if the scontext and tcontext match 
above then permission should be granted. I'll do some more reading but I 
thought I'd report back.

On 2/1/11 4:25 PM, "Dan Horák" <[email protected]> wrote:

you need this
http://docs.fedoraproject.org/en-US/Fedora/13/html/Security-Enhanced_Linux/sect-Security-Enhanced_Linux-Working_with_SELinux-SELinux_Contexts_Labeling_Files.html
and for the right value of the context I would check other files from
the net-snmp package and/or the selinux policy sources

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390
----------------------------------------------------------------------
For more information on Linux on System z, visit
http://wiki.linuxvm.org/

Reply via email to