Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Servers & Networking
FedoraForum Search

Forgot Password? Join Us!

Servers & Networking Discuss any Fedora server problems and Networking issues such as dhcp, IP numbers, wlan, modems, etc.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 21st June 2005, 04:35 PM
heq99 Offline
Registered User
 
Join Date: Jun 2005
Posts: 2
FC4/BIND/zone file permission deny

I created a domain and setup the DNS for test. All work well. But when I uploaded my actual zone file from windiows client and restarted named, it said permission denied for the uploaded zone file.

Then I replaced it with the test zone file. It worked again. I downloaded the test zone file and then uploaded the test zone file. It absolutely is same file, but couldn't work!

At last, I disabled the SELinux. Everything worked. I don't know why. Who can explain?

Thanks.
Reply With Quote
  #2  
Old 21st June 2005, 08:00 PM
jordanvanbergen Offline
Registered User
 
Join Date: Jun 2005
Posts: 9
How did you disable SELinux? What's the command line to do this? I might need this as well to test my cyrus-imapd problems.

I know that with SELinux you have to set some directory settings for it to work. This is what I had to do to get virtualhosts to work in apache in a different directory, let's say /web:

ls -Z /dir/where/www/root/will/be
chcon -R -h -t httpd_sys_content_t /dir/where/www/root/will/be for example /web
ls -Z /dir/where/www/root/will/be

this httpd_sys_content_t is voor apache dirs to be accesible. I assume it might be needed (different values of course) for a bind directory? I'm new to SELinux, so not an expert but it might not work because of the above explained things that happened to me. I ftp'ed a website to my home dir, copied it to /web and suddenly the website didn't work any longer (permission denied). I had to set this httpd_sys_content_t to make it work again. Perhaps it's the same for the bind directory?

Hope you can answer my question on how to disable SELinux and how to switch it on again using a shell?

Regards

Jordan van Bergen
Reply With Quote
  #3  
Old 21st June 2005, 11:20 PM
elliss Offline
Registered User
 
Join Date: May 2005
Location: Wales, UK
Posts: 127
jordanvanbergen - I think that you can turn SELinux on and off without the graphical tool by editing /etc/sysconfig/selinux, and rebooting.

heq99 - If you copy a file into a new directory the SELinux attributes of the file are updated, so try uploading your zone files to your account and then copying them to /var/named/. Uploading files direct to /var/named/ would be unsafe anyhow, since you'd have to login directly as root to do it...
Reply With Quote
  #4  
Old 22nd June 2005, 12:40 PM
heq99 Offline
Registered User
 
Join Date: Jun 2005
Posts: 2
Quote:
Originally Posted by elliss
heq99 - If you copy a file into a new directory the SELinux attributes of the file are updated, so try uploading your zone files to your account and then copying them to /var/named/. Uploading files direct to /var/named/ would be unsafe anyhow, since you'd have to login directly as root to do it...

Thank you very much. In fact, I did as you said. But because I was testing. So I used root to do these things. I downloaded the zone files from /var/named directly, then uploaded them into /root, then copy them to /var/named to overwrite the original, then restart BIND. Then the BIND displayed permission denied.
Reply With Quote
  #5  
Old 25th June 2005, 04:11 PM
elliss Offline
Registered User
 
Join Date: May 2005
Location: Wales, UK
Posts: 127
It sounds like you may have moved rather than copied the files - moving files doesn't reset the SELinux attributes on the files as copying does.
Reply With Quote
Reply

Tags
deny, fc4 or bind or zone, file, permission

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Current GMT-time: 10:24 (Wednesday, 22-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat