Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Using Fedora
FedoraForum Search

Forgot Password? Join Us!

Using Fedora General support for current versions. Ask questions about Fedora and it's software that do not belong in any other forum.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 25th November 2004, 09:43 AM
rhoekstra Offline
Registered User
 
Join Date: Nov 2004
Posts: 22
How set SELinux right on FC3 after upgrade?

Hi,

I upgraded from FC2 to FC3 on my laptop and for sake of testing I wanted to enable SELinux, as I hadn't enabled it on FC2. The reason for not enabling it on FC2 is that I am using ReiserFS.

I saw FC3 DOES support SELinux on Reiserfs (doing a ls -Z on / does show me all roles, that made me conclude it is working now).

Though, when I enabled SELinux (permissive), I saw bunch of audits in my log files, so I did a setfiles relabel. (strict policies, not to make it easy on myself ).

on http://www.hoekstra.nu/~robert/denied.txt there is a list of audits from boot time until just after I logged on. It shows both denial in dmesg as in /var/log/messages. Is there something I am doing wrong when enabling selinux?

The laptop is prety much out-of-the-box installed FC2 upgraded to FC3. At least init shouldn't get denial audits I would say?

Any help appreciated.
Reply With Quote
  #2  
Old 25th November 2004, 10:04 AM
rhoekstra Offline
Registered User
 
Join Date: Nov 2004
Posts: 22
Additionally, I get this when I try to relabel the system from the policy/src directory, I get the following output:

/usr/sbin/setfiles file_contexts/file_contexts `mount | grep -v "context=" | egrep -v '\((|.*,)bind(,.*|)\)' | awk '/(ext[23]| xfs|reiserfs).*rw/{print $3}';`
/usr/sbin/setfiles: read 1499 specifications
/usr/sbin/setfiles: labeling files under /
/etc/selinux: Input/output error
/usr/sbin/setfiles: unable to obtain attribute for file /etc/selinux
/usr/sbin/setfiles: error while labeling files under /
make: *** [relabel] Error 1

This is logged in /var/log/messages:
kernel: ReiserFS: hda4: warning: Invalid hash for xattr (security.selinux) associated with [13 193324 0x0 SD]

This id '193324 0x0 SD' appears to be the directory /etc/selinux, and when trying:
setfattr -x security.selinux /etc/selinux/

I get 'permission denied'.

Last edited by rhoekstra; 25th November 2004 at 10:22 AM.
Reply With Quote
  #3  
Old 26th November 2004, 04:21 AM
Jman Offline
Registered User
 
Join Date: Mar 2004
Location: Minnesota, USA
Age: 27
Posts: 7,909
All I know is that the SELinux tab of the Security Level tool helps configure SELinux without resorting to the command line.
Reply With Quote
Reply

Tags
fc3, selinux, set, upgrade

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
SELinux prevents login after FC9 upgrade jak56 Security and Privacy 2 20th June 2008 12:04 AM
F8 upgrade from F7: SELinux issues rweed Security and Privacy 4 14th January 2008 05:26 AM
selinux: hand tweaking policieand yum selinux-policy updates: overriden or perserved? mbiggerstaff Security and Privacy 1 19th December 2007 12:02 PM
A bunch of selinux/audit messages after fc5 -> fc6 upgrade Belegdol Using Fedora 3 27th October 2006 03:55 PM


Current GMT-time: 06:04 (Wednesday, 22-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat