And I've just noticed saslauthd is being denied setuid, though it does not seem to cause any failure anywhere (no problems, nor errors in other maillog or messages) type=USER_ACCT msg=audit(1130532067.754:516): user pid=6257 uid=0 auid=4294967295 msg='PAM: accounting acct=nim : exe="/usr/libexec/dovecot/dovecot-auth" (hostname=?, addr=?, terminal=dovecot res=success)' type=AVC msg=audit(1130532220.600:517): avc: denied { setuid } for pid=6271 comm="saslauthd" capability=7 scontext=system_u:system_r:saslauthd_t:s0 tcontext=system_u:system_r:saslauthd_t:s0 tclass=capability type=SYSCALL msg=audit(1130532220.600:517): arch=c000003e syscall=105 success=yes exit=0 a0=0 a1=51d160 a2=315e2346f0 a3=515e20 items=0 pid=6271 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 comm="saslauthd" exe="/usr/sbin/saslauthd" type=USER_AUTH msg=audit(1130532220.608:518): user pid=2160 uid=0 auid=4294967295 msg='PAM: authentication acct=nim : exe="/usr/sbin/saslauthd" (hostname=?, addr=?, terminal=? res=success)' type=AVC msg=audit(1130532220.612:519): avc: denied { setuid } for pid=6272 comm="saslauthd" capability=7 scontext=system_u:system_r:saslauthd_t:s0 tcontext=system_u:system_r:saslauthd_t:s0 tclass=capability type=SYSCALL msg=audit(1130532220.612:519): arch=c000003e syscall=105 success=yes exit=0 a0=0 a1=51d380 a2=315e2346f0 a3=51d2f0 items=0 pid=6272 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 comm="saslauthd" exe="/usr/sbin/saslauthd" type=USER_ACCT msg=audit(1130532220.616:520): user pid=2160 uid=0 auid=4294967295 msg='PAM: accounting acct=nim : exe="/usr/sbin/saslauthd" (hostname=?, addr=?, terminal=? res=success)' type=USER_AUTH msg=audit(1130532234.605:521): user pid=6285 uid=0 auid=4294967295 msg='PAM: authentication acct=nim : exe="/usr/libexec/dovecot/dovecot-auth" (hostname=?, addr=?, terminal=dovecot res=success)' -- Nicolas Mailhot
Attachment:
signature.asc
Description: Ceci est une partie de message =?ISO-8859-1?Q?num=E9riquement?= =?ISO-8859-1?Q?_sign=E9e?=
-- fedora-selinux-list mailing list fedora-selinux-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-selinux-list