All of lore.kernel.org
 help / color / mirror / Atom feed
* Re: cannot login using strict policy
@ 2007-04-25 15:31 JanuGerman
  2007-04-25 15:44 ` Stephen Smalley
  0 siblings, 1 reply; 14+ messages in thread
From: JanuGerman @ 2007-04-25 15:31 UTC (permalink / raw)
  To: Karl MacMillan; +Cc: SELinux List, Stephen Smalley

Hi Karl,

Thanks for the response. I have to reboot with 'selinux=0' in order to diagnose the type of .bash_profile. It is 'root:object_r:user_home_t:s0'. This seems to me a problem, like every time, i will have to reboot with selinux=0, in order to get the attributes of the file. Plus one question regarding the unconfined_t. Is unconfined_t is changed to confined_t in strict policy mode?

Best,
JG

----- Original Message ----
From: Karl MacMillan <kmacmillan@mentalrootkit.com>
To: JanuGerman <doublemalam@yahoo.co.uk>
Cc: SELinux List <selinux@tycho.nsa.gov>; Stephen Smalley <sds@tycho.nsa.gov>
Sent: Wednesday, 25 April, 2007 5:20:28 PM
Subject: Re: cannot login using strict policy

On Wed, 2007-04-25 at 14:52 +0000, JanuGerman wrote:
> I have installed strict policy and then relabelled the files using 'fixfiles relablel' after rebooting with 'enforcing=0 single'. Every thing went well, but when i try to login, i get an error message that 
> localuser:root being added to access control list
> -/bin/bash: /root/.bash_profile: permission denied.
> Any idea?

What is the type on /root/.bash_profile? Any avcs?

Karl




--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.





      ___________________________________________________________
Yahoo! Answers - Got a question? Someone out there knows the answer. Try it
now.
http://uk.answers.yahoo.com/ 

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 14+ messages in thread
* Re: cannot login using strict policy
@ 2007-04-25 14:52 JanuGerman
  2007-04-25 15:20 ` Karl MacMillan
  0 siblings, 1 reply; 14+ messages in thread
From: JanuGerman @ 2007-04-25 14:52 UTC (permalink / raw)
  To: SELinux List; +Cc: Stephen Smalley

I have installed strict policy and then relabelled the files using 'fixfiles relablel' after rebooting with 'enforcing=0 single'. Every thing went well, but when i try to login, i get an error message that 
localuser:root being added to access control list
-/bin/bash: /root/.bash_profile: permission denied.
Any idea?
Best,
JG


      ___________________________________________________________
Yahoo! Answers - Got a question? Someone out there knows the answer. Try it
now.
http://uk.answers.yahoo.com/ 

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 14+ messages in thread
* cannot login using strict policy
@ 2007-04-25  7:34 JanuGerman
  0 siblings, 0 replies; 14+ messages in thread
From: JanuGerman @ 2007-04-25  7:34 UTC (permalink / raw)
  To: Stephen Smalley; +Cc: SELinux List

> Boot with 'enforcing=0 single', then run 'fixfiles
> relabel' if it
> doesn't automatically relabel, then reboot normally.


I installed strict policy and then relabelled the files using 'fixfiles relablel' after rebooting with 'enforcing=0 single'. Every thing went well, but when i try to login, i get an error message that 

localuser:root being added to access control list
-/bin/bash: /root/.bash_profile: permission denied.

Any idea?

Best,
JG


      ___________________________________________________________ 
Yahoo! Mail is the world's favourite email. Don't settle for less, sign up for
your free account today http://uk.rd.yahoo.com/evt=44106/*http://uk.docs.yahoo.com/mail/winter07.html 

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2007-05-30  7:11 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-04-25 15:31 cannot login using strict policy JanuGerman
2007-04-25 15:44 ` Stephen Smalley
2007-05-10  9:33   ` Ken YANG
2007-05-10 12:28     ` Stephen Smalley
2007-05-11  9:41       ` Ken YANG
2007-05-11 12:45         ` Stephen Smalley
2007-05-17  1:56           ` Ken YANG
2007-05-23  7:30           ` Ken YANG
2007-05-23 13:02             ` Daniel J Walsh
2007-05-24  6:56               ` Ken YANG
2007-05-30  7:08               ` Ken YANG
  -- strict thread matches above, loose matches on Subject: below --
2007-04-25 14:52 JanuGerman
2007-04-25 15:20 ` Karl MacMillan
2007-04-25  7:34 JanuGerman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.