Squid and SELinux

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



Hi.

I'm trying to setup squid with SELinux, the problem i encounter is taht i want to add another directory for cache, in this system we have a home partition with huge space, i create a squid dir and add the path with semanage:

semanage fcontext -a -t squid_cache_t '/home/squid(/.*)?'

i check the files and are in the good context:

drwxr-xr-x  squid squid user_u:object_r:squid_cache_t    .
drwxr-xr-x  squid squid system_u:object_r:home_root_t  ..
drwxr-x---  squid squid user_u:object_r:squid_cache_t    00
drwxr-x---  squid squid user_u:object_r:squid_cache_t    01
...

But when i want start it i get this:

type=AVC msg=audit(1296442326.932:739661): avc:  denied  { search } for  pid=30924 comm="squid" name="/" dev=sda3 ino=2 scontext=user_u:system_r:squid_t:s0 tcontext=system_u:object_r:home_root_t:s0 tclass=dir

I know that the solution is to mount the huge partition on /var/spool/squid, i'm a newbie to SELinux, and want to know if it's posible to archive this.

Regards.
_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos

[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux