Hi, This has been reported to the Debian BTS. semanage does not set the umask for itself and does not fix the permissions of rewritten files. This leads to a unreadable (for generic user and therfor ssh) seusers file: -rw-r----- 1 root root 187 17. Apr 16:22 /etc/selinux/default/seusers The pam module does not bail out on that but always assigns user_u for users. manoj http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=524508 -- Manoj Srivastava <srivasta@xxxxxxx> <http://www.golden-gryphon.com/> 1024D/BF24424C print 4966 F272 D093 B493 410B 924B 21BA DABB BF24 424C -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.