Thanks. I used the chcon command to change the context but am still having
problems and seeing this in the audit log:
type=AVC msg=audit(1296596790.809:1547): avc: denied { execute } for
pid=14580 comm="snmpd" path="/usr/lib64/snmp/dlmod/dynamo.so" dev=dm-3
ino=45864 scontext=unconfined_u:system_r:snmpd_t:s0
tcontext=unconfined_u:system_r:snmpd_t:s0 tclass=file
type=SYSCALL msg=audit(1296596790.809:1547): arch=80000016 syscall=90
per=400000 success=no exit=-13 a0=3ffffb17160 a1=6650 a2=5 a3=802 items=0
ppid=1 pid=14580 auid=503 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0
fsgid=0 tty=(none) ses=183 comm="snmpd" exe="/usr/sbin/snmpd"
subj=unconfined_u:system_r:snmpd_t:s0 key=(null)
ls -RlZ /usr/lib64/snmp/
/usr/lib64/snmp/:
drwxr-xr-x. root root unconfined_u:system_r:snmpd_t:s0 dlmod
/usr/lib64/snmp/dlmod:
-rwxr-xr-x. root root unconfined_u:system_r:snmpd_t:s0 dynamo.so
I am probably being naïve in believing that if the scontext and tcontext match
above then permission should be granted. I'll do some more reading but I
thought I'd report back.
On 2/1/11 4:25 PM, "Dan Horák" <[email protected]> wrote:
you need this
http://docs.fedoraproject.org/en-US/Fedora/13/html/Security-Enhanced_Linux/sect-Security-Enhanced_Linux-Working_with_SELinux-SELinux_Contexts_Labeling_Files.html
and for the right value of the context I would check other files from
the net-snmp package and/or the selinux policy sources
----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390
----------------------------------------------------------------------
For more information on Linux on System z, visit
http://wiki.linuxvm.org/