Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 25th May 2006, 03:12 PM
Evil-I Offline
Registered User
 
Join Date: Nov 2004
Posts: 90
Exclamation Enabled SELINUX now can't login....

Hi there,

I was sorting out security on my recently installed FC5 box, I enabled the firewall with all the appropriate ports added etc and decided to turn on SELINUX in enforce mode as well (not having used this before....should have known better I suppose). Now I can't get into my box either by ssh (it asks for username and password then closes the puttyssh viewer once you hit enter on the password) or locally (input username and password then get an error message saying "cannot start the session as there has been an internal error")

The next dialogue that appears tells me that as my session lasted less than 10 seconds etc..... but does give me a tick box to see the (-/.xsession-errors file with following content.

/etc/gdm/PreSession/Default: Registering your session with wtmp and utmp
/etc/gdm/PreSession/Default: running: usr/bin/sessreg -a -w /var/log/wtmp -u /var/run/utmp -x "/var/gdm/:0.Xservers" -h "" -l ":0" "server"
session_child_run: Could not exec /etc/X11/xinit/Xsession default

I've not tried using linux rescue or anything to try and get into the box yet, to be honest just being able to turn selinux off would be fine by me. Can anyone suggest a. Whats happened and b. a way to make it stop!

Any help greatly appreciated,

E-I
Reply With Quote
  #2  
Old 25th May 2006, 03:31 PM
jbannon Offline
Registered User
 
Join Date: Dec 2005
Posts: 909
Can you login at the console as root? If so, try tying the following:

setsebool -P allow_execstack=1
setsebool -P allow_execmod=1

This should allow you to get into X. You also need to sort out the ssh side as I don't think it's just enough to trust it as a service in the firewall. I don't know how to do this last bit though.
__________________
Best regards,
Jim Bannon
(Registered Linux User #405603 :) )
Reply With Quote
  #3  
Old 25th May 2006, 03:58 PM
Evil-I Offline
Registered User
 
Join Date: Nov 2004
Posts: 90
Thanks for reply,

I've not been able to get terminal access from within the FC5 login screen as it always gives me the same error messages as above.

I booted from my Install DVD did 'linux rescue' and 'chroot /mnt/sysimage' then su for root. I ran the commands you suggested, unfotunately there was no change once I'd rebooted, same error messages as before.

Is there any way of disabling selinux from linux rescue? Its only a home server and I'm sure it will be fine with just its internal firewall and being behind a firewalled router as well.

Feel like I've opened pandoras box.... must keep reminding myself to not randomly turn things on in linux without having a good idea of what its going to do....Bugger!

Thanks again,

E-I
Reply With Quote
  #4  
Old 25th May 2006, 04:18 PM
Evil-I Offline
Registered User
 
Join Date: Nov 2004
Posts: 90
Got it sorted.....

Found this post by a very helpful chap on how to disable selinux in console from linux rescue.

http://forums.fedoraforum.org/forum/...elinux+console

I think SElinux is going to stay off for now until I have some time to get my head round it!
Thanks for your help,

E-I
Reply With Quote
  #5  
Old 25th May 2006, 04:45 PM
jbannon Offline
Registered User
 
Join Date: Dec 2005
Posts: 909
Yeah, I just looked it up on the manual page and then at /etc/selinux/config to see how it should be done. Funny thing though is that I haven't had any problems with selinux other than not setting allow_execstack and allow_execmod after upgrading the kernel and installing kmod-fglrx (you either get a blank screen or the menu panels appear but nothing is on them and dmesg tells you it can't reset to use the module properly). Documentation on selinux is kind of scanty, the books I have show how to set it but don't tell you what any of the variables actually do and if you set the above variables and look in /selinux they appear there but don't appear in the GUI admin tool. I leave it on for safety's sake but I don't suppose it's needed really for a home desktop. A server would be another matter however if it's open to the internet or in a DMZ.
__________________
Best regards,
Jim Bannon
(Registered Linux User #405603 :) )
Reply With Quote
  #6  
Old 25th May 2006, 05:13 PM
Evil-I Offline
Registered User
 
Join Date: Nov 2004
Posts: 90
This machine IS a server, although the only thing open to the internet is the teamspeak voice communication software, as well as the basic firewall setup in FC5 its also sat behind a router that has a SPI firewall built in, so hopefully that will be fine for my needs.

Anyway, thanks very much for your help my freind, its always appreciated!

Best,

E-I
Reply With Quote
Reply

Tags
enabled, login, selinux

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Selinux, automount .iso with selinux enabled? leadgolem Security and Privacy 0 15th September 2007 01:37 AM
why would i want to keep SELinux enabled? sirbrett Using Fedora 8 11th May 2005 08:19 AM


Current GMT-time: 19:22 (Tuesday, 21-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat