F12 beta, ldap authentication and NFS mounted home

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I upgraded a machine from F10 to F12 beta - its a client machine that
mounts /home over NFS and authenticates over LDAP (however, its a mac
server that sets /home as /Volumes/Homes, which I have set up as a
pointer to /home). use_nfs_home_dirs is on and I can log in via SSH or
the console, but the graphical login fails when clicking "log in" with
the following selinux error:

SELinux is preventing /usr/libexec/ck-get-x11-server-pid "read" access
on Homes.

I've attached the full sealart, am I missing something obvious/simple?

Thanks for any help!
-Tim

-- 
---------------------------------------------------------

        Tim Fenn
        fenn@xxxxxxxxxxxx
        Stanford University, School of Medicine
        James H. Clark Center
        318 Campus Drive, Room E300
        Stanford, CA  94305-5432
        Phone:  (650) 736-1714
        FAX:  (650) 736-1961

---------------------------------------------------------

Summary:

SELinux is preventing /usr/libexec/ck-get-x11-server-pid "read" access on Homes.

Detailed Description:

SELinux denied access requested by ck-get-x11-serv. It is not expected that this
access is required by ck-get-x11-serv and this access may signal an intrusion
attempt. It is also possible that the specific version or configuration of the
application is causing it to require additional access.

Allowing Access:

You can generate a local policy module to allow this access - see FAQ
(http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Please file a bug
report.

Additional Information:

Source Context                system_u:system_r:consolekit_t:s0-s0:c0.c1023
Target Context                unconfined_u:object_r:default_t:s0
Target Objects                Homes [ lnk_file ]
Source                        ck-get-x11-serv
Source Path                   /usr/libexec/ck-get-x11-server-pid
Port                          <Unknown>
Host                          XXXXXX.stanford.edu
Source RPM Packages           ConsoleKit-x11-0.4.1-1.fc12
Target RPM Packages           
Policy RPM                    selinux-policy-3.6.32-27.fc12
Selinux Enabled               True
Policy Type                   targeted
MLS Enabled                   True
Enforcing Mode                Enforcing
Plugin Name                   catchall
Host Name                     XXXXXX.stanford.edu
Platform                      Linux XXXXXX.stanford.edu 2.6.31.1-56.fc12.x86_64
                              #1 SMP Tue Sep 29 16:16:22 EDT 2009 x86_64 x86_64
Alert Count                   5
First Seen                    Wed Oct 21 16:35:50 2009
Last Seen                     Wed Oct 21 16:44:51 2009
Local ID                      6707cb82-aa80-4b60-8ade-44532583e08f
Line Numbers                  

Raw Audit Messages            

node=XXXXXX.stanford.edu type=AVC msg=audit(1256168691.455:24129): avc:  denied  { read } for  pid=2716 comm="ck-get-x11-serv" name="Homes" dev=dm-0 ino=218 scontext=system_u:system_r:consolekit_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:default_t:s0 tclass=lnk_file

node=XXXXXXX.stanford.edu type=SYSCALL msg=audit(1256168691.455:24129): arch=c000003e syscall=21 success=no exit=-13 a0=7fff8c2a3f54 a1=4 a2=3 a3=fffffffffffffb8d items=0 ppid=2715 pid=2716 auid=4294967295 uid=1029 gid=20 euid=1029 suid=1029 fsuid=1029 egid=20 sgid=20 fsgid=20 tty=(none) ses=4294967295 comm="ck-get-x11-serv" exe="/usr/libexec/ck-get-x11-server-pid" subj=system_u:system_r:consolekit_t:s0-s0:c0.c1023 key=(null)



--
fedora-selinux-list mailing list
fedora-selinux-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-selinux-list

[Index of Archives]     [Fedora Users]     [Fedora Desktop]     [Big List of Linux Books]     [Yosemite News]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux