All of lore.kernel.org
 help / color / mirror / Atom feed
* Postfix with domain keys
@ 2009-01-06 12:06 Martin Spinassi
  2009-01-06 13:22 ` Stephen Smalley
  2009-01-06 22:24 ` Russell Coker
  0 siblings, 2 replies; 12+ messages in thread
From: Martin Spinassi @ 2009-01-06 12:06 UTC (permalink / raw)
  To: selinux

Hello list!


I'm a little stuck with selinux and postfix, hope you can give me
feedback with it.

We're trying to add domain keys to a postfix server, but it can't open
ports used by dkim to sign the mail. Here is some output of audit.log:


type=AVC msg=audit(1231242373.605:52): avc:  denied  { name_bind } for
pid=5386 comm="master" src=10026
scontext=root:system_r:postfix_master_t:s0
tcontext=system_u:object_r:postfix_master_t:s0 tclass=tcp_socket

type=SYSCALL msg=audit(1231242373.605:52): arch=c000003e syscall=49
success=no exit=-13 a0=11 a1=2b06cdbc46d0 a2=10 a3=7fffe2d2f64c items=0
ppid=1 pid=5386 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0
fsgid=0 tty=(none) ses=3 comm="master" exe="/usr/libexec/postfix/master"
subj=root:system_r:postfix_master_t:s0 key=(null)



I've allready added the port to the postfix_master_t domain with:
# semanage port -a -t postfix_master_t -p tcp 10026


Here is the maillog output:

postfix/postfix-script: starting the Postfix mail system
postfix/master[5386]: fatal: bind 127.0.0.1 port 10026: Permission
denied


It's a RHEL 5.2 and kernel 2.6.18-92.1.22.el5.



Any kind of help is appreciated :)


Cheers


Martín


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2009-01-07 12:20 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-01-06 12:06 Postfix with domain keys Martin Spinassi
2009-01-06 13:22 ` Stephen Smalley
2009-01-06 13:30   ` Stephen Smalley
2009-01-06 13:58     ` Martin Spinassi
2009-01-06 14:13       ` Stephen Smalley
2009-01-06 14:58         ` Martin Spinassi
2009-01-06 14:53           ` Stephen Smalley
2009-01-06 15:17             ` Martin Spinassi
2009-01-06 13:55   ` Martin Spinassi
2009-01-06 14:06     ` Stephen Smalley
2009-01-06 22:24 ` Russell Coker
2009-01-07 12:33   ` Martin Spinassi

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.