Just FYI, I installed the rawhide policy and it does fix this problem. The system boots fine in enforcing mode. Lots of other denials, most of which are from pam_console_app but also some that keep boot-time NFS mounts from working. I'm assuming it's just not a good idea to be running the rawhide policy on otherwise stock FC5, so I'll go back to permissive mode with the old policy until an update arrives. If, however, you'd like for me to report problems then I'd be happy to do so. I gather that I'm the only person running FC5, selinux and LDAP over SSL so perhaps my setup is odd in other ways that may be useful to you. - J< -- fedora-selinux-list mailing list fedora-selinux-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-selinux-list