Re: [CentOS] selinux policy (& engine) broken in C7

2020-11-20 Thread Marc Balmer via CentOS
> Am 20.11.2020 um 19:50 schrieb lejeczek via CentOS : > > hi guys > > I've just gotten a bunch of updates via yum and something > weird seems to be going on after the update. > System has: > > selinux-policy-3.13.1-268.el7_9.2.noarch > selinux-policy-targeted-3.13.1-268.el7_9.2.noarch > >

Re: [CentOS] Desktop Over NFS Home Blocked By Firewalld

2020-11-20 Thread Michael B Allen
On Fri, Nov 20, 2020 at 6:37 PM Gordon Messmer wrote: > > On 11/20/20 1:26 PM, Michael B Allen wrote: > > Thanks for the inputs but my problem has nothing to do with NFS. > > > Do you think that because you saw "krbupdate" in /etc/services? > > The problem you've described is definitely an NFSv3

Re: [CentOS] Desktop Over NFS Home Blocked By Firewalld

2020-11-20 Thread Gordon Messmer
On 11/20/20 1:26 PM, Michael B Allen wrote: Thanks for the inputs but my problem has nothing to do with NFS. Do you think that because you saw "krbupdate" in /etc/services? The problem you've described is definitely an NFSv3 problem.  The connections causing the client to hang are portmap

Re: [CentOS] Desktop Over NFS Home Blocked By Firewalld

2020-11-20 Thread Michael B Allen
On Fri, Nov 20, 2020 at 2:52 PM Chris Schanzle wrote: > > On 11/20/20 2:31 PM, Michael B Allen wrote: > > On Fri, Nov 20, 2020 at 2:06 PM Michael B Allen wrote: > >> Apparently I don't know how to do "that" because this: > >> > >> # iptables -A INPUT -p tcp --sport 760 -m conntrack --ctstate >

Re: [CentOS] Desktop Over NFS Home Blocked By Firewalld

2020-11-20 Thread Chris Schanzle via CentOS
On 11/20/20 2:31 PM, Michael B Allen wrote: > On Fri, Nov 20, 2020 at 2:06 PM Michael B Allen wrote: >> Apparently I don't know how to do "that" because this: >> >> # iptables -A INPUT -p tcp --sport 760 -m conntrack --ctstate >> NEW,ESTABLISHED -j ACCEPT >> >> still doesn't allow the traffic

Re: [CentOS] Desktop Over NFS Home Blocked By Firewalld

2020-11-20 Thread Gordon Messmer
On 11/20/20 11:31 AM, Michael B Allen wrote: I can't log into a desktop with an nfs home dir without punching a reverse hole in my firewall? That shouldn't be. I'm pretty sure your client is using NFSv3, and the ports you need opened are for RPC, and they *are* dynamic (so the next time

Re: [CentOS] Desktop Over NFS Home Blocked By Firewalld

2020-11-20 Thread Michael B Allen
On Fri, Nov 20, 2020 at 2:06 PM Michael B Allen wrote: > Apparently I don't know how to do "that" because this: > > # iptables -A INPUT -p tcp --sport 760 -m conntrack --ctstate > NEW,ESTABLISHED -j ACCEPT > > still doesn't allow the traffic through (not that I would want to > allow an --sport

Re: [CentOS] Desktop Over NFS Home Blocked By Firewalld

2020-11-20 Thread Michael B Allen
On Fri, Nov 20, 2020 at 12:18 PM Frank Cox wrote: > > On Fri, 20 Nov 2020 12:07:40 -0500 > Michael B Allen wrote: > > > So TCP src 760 to 41285. What's that? > > Apparently "that" is what you need to allow in order for your desktop to work. > > What it is actually doing, I'm not sure. Google

[CentOS] selinux policy (& engine) broken in C7

2020-11-20 Thread lejeczek via CentOS
hi guys I've just gotten a bunch of updates via yum and something weird seems to be going on after the update. System has: selinux-policy-3.13.1-268.el7_9.2.noarch selinux-policy-targeted-3.13.1-268.el7_9.2.noarch actually three different boxes, all the same: $ semodule -l No modules. and an

Re: [CentOS] Desktop Over NFS Home Blocked By Firewalld

2020-11-20 Thread Frank Cox
On Fri, 20 Nov 2020 12:07:40 -0500 Michael B Allen wrote: > So TCP src 760 to 41285. What's that? Apparently "that" is what you need to allow in order for your desktop to work. What it is actually doing, I'm not sure. Google tells me that port 760 has something to do with Kerberos

Re: [CentOS] Desktop Over NFS Home Blocked By Firewalld

2020-11-20 Thread Michael B Allen
On Fri, Nov 20, 2020 at 11:19 AM Frank Cox wrote: > > So firewalld is blocking something that the Fedora desktop needs. What > > is it? What services do I need to add to firewalls? > > https://www.cyberciti.biz/faq/enable-firewalld-logging-for-denied-packets-on-linux/ Hi Frank, Thanks for that

Re: [CentOS] Desktop Over NFS Home Blocked By Firewalld

2020-11-20 Thread Frank Cox
On Fri, 20 Nov 2020 11:05:25 -0500 Michael B Allen wrote: > So firewalld is blocking something that the Fedora desktop needs. What > is it? What services do I need to add to firewalls? https://www.cyberciti.biz/faq/enable-firewalld-logging-for-denied-packets-on-linux/ -- Can we uninstall 2020

[CentOS] Desktop Over NFS Home Blocked By Firewalld

2020-11-20 Thread Michael B Allen
Hi, Just installed CentOS 7 that serves a home dir automounted over nfs. SELinux is disabled. If I go to the client (oldish version of Fedora) doing su - username works fine and the nfs export is mounted and I can see all files and everything seems well. But trying to actually login to the

[CentOS] CentOS-announce Digest, Vol 188, Issue 4

2020-11-20 Thread centos-announce-request
Send CentOS-announce mailing list submissions to centos-annou...@centos.org To subscribe or unsubscribe via the World Wide Web, visit https://lists.centos.org/mailman/listinfo/centos-announce or, via email, send a message with subject or body 'help' to