Re: [Freeipa-users] SELinux is preventing /usr/sbin/krb5kdc from write access on the sock_file /var/lib/sss/pipes/pac.

2016-09-17 Thread lejeczek

I think one case it when I sudo
not much there really, building up an semodule out of the 
alerts would end up in: allow krb5kdc_t 
sssd_var_lib_t:sock_file write;



On 17/09/16 12:59, Lukas Slebodnik wrote:

On (17/09/16 12:02), lejeczek wrote:

before I drop above onto SELinux team - do you guys think SE should be doing
that? Does it impair IPA in some ways?


It would be god to see more details. Do you know which action trigger
AVCs?

Could you also provide detail about AVC?
ausearch -m avc -i ts recent

LS


--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project


Re: [Freeipa-users] SELinux is preventing /usr/sbin/krb5kdc from write access on the sock_file /var/lib/sss/pipes/pac.

2016-09-17 Thread Lukas Slebodnik
On (17/09/16 12:02), lejeczek wrote:
>before I drop above onto SELinux team - do you guys think SE should be doing
>that? Does it impair IPA in some ways?
>
It would be god to see more details. Do you know which action trigger
AVCs?

Could you also provide detail about AVC?
ausearch -m avc -i ts recent

LS

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project


[Freeipa-users] SELinux is preventing /usr/sbin/krb5kdc from write access on the sock_file /var/lib/sss/pipes/pac.

2016-09-17 Thread lejeczek
before I drop above onto SELinux team - do you guys think SE 
should be doing that? Does it impair IPA in some ways?


many thanks
L.

--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project