All of lore.kernel.org
 help / color / mirror / Atom feed
* login process
@ 2003-10-10 20:30 Carlos Anísio Monteiro
  0 siblings, 0 replies; 3+ messages in thread
From: Carlos Anísio Monteiro @ 2003-10-10 20:30 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 589 bytes --]

Hi.

1) Always that login at system, it request the role and the type. (it is 
not very clearly, excuse).

The message is the one that follows:

boot process ...

login:   root
password: *******
*Login: unable to obtain context for root
Would you like to enter a security context? [y] *

I answer y.

Enter role   *sysadm_r*
Enter type   *sysadm_t*

messages AVC: denied. *The login process is OK*.

I have always that  to provide this role and type?
I think that login process not is recognize the files of context 
(/etc/security/default_type or /etc/security/default_context).

Thanks.

[-- Attachment #2: Type: text/html, Size: 863 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

* login process
@ 2003-10-13  8:20 Carlos Anísio Monteiro
  2003-10-13 12:28 ` Russell Coker
  0 siblings, 1 reply; 3+ messages in thread
From: Carlos Anísio Monteiro @ 2003-10-13  8:20 UTC (permalink / raw)
  To: selinux, Carlos Anísio Monteiro

[-- Attachment #1: Type: text/plain, Size: 1 bytes --]



[-- Attachment #2: login process --]
[-- Type: message/rfc822, Size: 4321 bytes --]

[-- Attachment #2.1.1: Type: text/plain, Size: 589 bytes --]

Hi.

1) Always that login at system, it request the role and the type. (it is 
not very clearly, excuse).

The message is the one that follows:

boot process ...

login:   root
password: *******
*Login: unable to obtain context for root
Would you like to enter a security context? [y] *

I answer y.

Enter role   *sysadm_r*
Enter type   *sysadm_t*

messages AVC: denied. *The login process is OK*.

I have always that  to provide this role and type?
I think that login process not is recognize the files of context 
(/etc/security/default_type or /etc/security/default_context).

Thanks.

[-- Attachment #2.1.2: Type: text/html, Size: 863 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: login process
  2003-10-13  8:20 Carlos Anísio Monteiro
@ 2003-10-13 12:28 ` Russell Coker
  0 siblings, 0 replies; 3+ messages in thread
From: Russell Coker @ 2003-10-13 12:28 UTC (permalink / raw)
  To: Carlos Anísio Monteiro, selinux

The most likely cause of that problem is the login process running in the 
wrong domain.  The set of acceptable contexts for the user process is 
determined from the context of the login process (should be 
system_u:object_r:local_login_t) and the file /etc/security/default_contexts.

Assuming that your default_contexts file has the correct data (most likely as 
it a default install will put the right file there) then the problem is the 
context of the login process.

If you run "ps ax --context | grep login" then you'll see the context.

The wrong context can be caused by /bin/login having the wrong type 
(ls --context to inspect it) or by the parent process (getty) running in the 
wrong context.


PS  If you have problems sending to the list please paste the text into a new 
message rather than forwarding.  Forwarding tends to leave the message as an 
attachment and break quoting.

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2003-10-13 12:28 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-10-10 20:30 login process Carlos Anísio Monteiro
  -- strict thread matches above, loose matches on Subject: below --
2003-10-13  8:20 Carlos Anísio Monteiro
2003-10-13 12:28 ` Russell Coker

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.