All of lore.kernel.org
 help / color / mirror / Atom feed
* sshd error: Failed to get default security context
@ 2009-10-17  0:15 Larry Ross
  2009-10-17 11:39 ` Daniel J Walsh
  0 siblings, 1 reply; 34+ messages in thread
From: Larry Ross @ 2009-10-17  0:15 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 1274 bytes --]

I have created a custom selinux user for the strict policy on RHEL5.3 who's
purpose is to connect via ssh and scp files off the machine.  When that user
tries to login via ssh, I see the following messages in /var/log/secure:

In enforcing:
Oct 16 07:49:40 localhost sshd[20461]: Accepted password for scpuser
from 192.168.1.1 port 64680 ssh2
Oct 16 07:49:40 localhost sshd[20461]: error: Failed to get default security
context for scpuser.
Oct 16 07:49:40 localhost sshd[20461]: fatal: SELinux failure. Aborting
connection.

In permissive:
Oct 16 07:55:59 localhost sshd[23302]: Accepted password for scpuser from
192.168.1.1 port 56254 ssh2
Oct 16 07:55:59 localhost sshd[23302]: error: Failed to get default security
context for scpuser.
Oct 16 07:55:59 localhost sshd[23302]: error: SELinux failure. Continuing in
permissive mode.

Could someone explain what these messages mean?

I believe that I have a default context defined in the "default context"
file that should work. I believe I have an executable context available for
this user (using rbash rather than bash).

How is sshd making this decision?  It looks like it is calling setexeccon,
but I'm not sure how that makes its decision.  Where should I look for clues
as to how to fix it?

   Thank you,
   Larry

[-- Attachment #2: Type: text/html, Size: 1514 bytes --]

^ permalink raw reply	[flat|nested] 34+ messages in thread

end of thread, other threads:[~2009-12-16 15:48 UTC | newest]

Thread overview: 34+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-10-17  0:15 sshd error: Failed to get default security context Larry Ross
2009-10-17 11:39 ` Daniel J Walsh
2009-10-17 18:17   ` Larry Ross
2009-10-19 13:53     ` Stephen Smalley
2009-10-19 16:49       ` Larry Ross
2009-10-19 17:13         ` Stephen Smalley
2009-10-20  1:43           ` Larry Ross
2009-10-20 11:18             ` Stephen Smalley
2009-10-27  1:16               ` Where do I get a good Policy Base ? Hasan Rezaul-CHR010
2009-10-27  8:49                 ` Dominick Grift
2009-10-27 12:45                   ` Christopher J. PeBenito
2009-11-10  0:01                   ` Hasan Rezaul-CHR010
2009-12-10  2:18                     ` How to use sepolgen VS. policygentool Hasan Rezaul-CHR010
2009-12-10  2:50                       ` Hasan Rezaul-CHR010
2009-12-10 16:02                         ` Stephen Smalley
2009-12-10 17:11                         ` Guido Trentalancia
2009-12-10 19:11                         ` Daniel J Walsh
2009-12-10 15:54                       ` Stephen Smalley
2009-12-10 19:38                         ` Daniel J Walsh
2009-12-15 17:43                         ` Policy writing philosophy Hasan Rezaul-CHR010
2009-12-15 20:14                           ` Dominick Grift
2009-12-15 20:40                           ` Bandan Das
2009-12-16 14:58                           ` Stephen Smalley
2009-12-16 15:30                             ` Hasan Rezaul-CHR010
2009-12-16 15:47                               ` Stephen Smalley
2009-12-16 15:48                                 ` Hasan Rezaul-CHR010
2009-12-10 19:04                       ` How to use sepolgen VS. policygentool Daniel J Walsh
2009-11-11 19:37                   ` Where do I get a good Policy Base ? Hasan Rezaul-CHR010
2009-11-11 22:02                     ` Daniel J Walsh
2009-11-11 23:25                       ` Hasan Rezaul-CHR010
2009-11-12 13:06                         ` Daniel J Walsh
2009-10-18 10:33   ` sshd error: Failed to get default security context Dominick Grift
2009-10-18 18:58     ` Larry Ross
2009-10-19 14:02       ` Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.