Re: Change of /etc/selinux/config's SELINUX causes port389 fail to start

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, 2016-04-07 at 15:27 -0700, Gordon Messmer wrote:
> On 04/07/2016 03:15 PM, William Brown wrote:
> > 
> > When you change from permissive to enforcing, you often need to re-label to
> > make
> > sure the system is consistent.
>  From "permissive"?  I know that's true if a system is set to enforcing 
> from "disabled" but I've never seen an indication that switching from 
> permissive would require a re-label.
> 
> Do you know what would cause permissive mode to mislabel filesystem objects?


When you go from disabled to permissive, then to enforcing, this is very true,
because then no objects have labels.

The issue with permissive to enforcing, is that people may have been mv-ing
directories around, putting things in the wrong locations (so they have the
correct label for where they are, but wrong relative to the application). 

There certainly won't be as many issues as disabled -> permissive, but there are
still enough subtle things that can change an go wrong, that it's worth the
relabel to be sure that your issues going from perm -> enforce are not related to
mislabeling, but perhaps other issues.



-- 
Sincerely,

William Brown
Software Engineer
Red Hat, Brisbane

Attachment: signature.asc
Description: This is a digitally signed message part

--
389 users mailing list
389-users@%(host_name)s
http://lists.fedoraproject.org/admin/lists/389-users@xxxxxxxxxxxxxxxxxxxxxxx

[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux