All of lore.kernel.org
 help / color / mirror / Atom feed
* Selinux in enforcing mode prevent network interface to be configured at boot for Debian stable ( 5.0)
@ 2010-02-07  8:12 Elko Kuric
  2010-02-07  8:42 ` Justin P. Mattock
  2010-02-07 16:16 ` Michal Svoboda
  0 siblings, 2 replies; 8+ messages in thread
From: Elko Kuric @ 2010-02-07  8:12 UTC (permalink / raw)
  To: selinux

Hi all,

I decided to move my debian installation to use Selinux, and I
installed it using

http://wiki.debian.org/SELinux  howto ( Debian 5 )


When Selinux is in "permissive" mode, network connection is up and it works
but when I switch Selinux to "enforcing" mode network interface is
down after reboot.

seaudit-report report the following output:

Feb 07 08:36:58 firewall kernel: avc: denied pid=1290 comm=ifup
name=ifstate ino=4103 dev=hda1 \
scontext=system_u:system_r:udev_t
tcontext=system_u:object_r:etc_runtime_t tclass=file

Feb 07 08:36:58 firewall kernel: avc: denied pid=1297 comm=ifup
name=ifstate ino=4103 dev=hda1 \
scontext=system_u:system_r:udev_t
tcontext=system_u:object_r:etc_runtime_t tclass=file

I can understand that selinux is preventing ifup to be executed, but I
still do not have counterpart in debian
for RedHat's

sealert -a audit.log

, where it suggest what is necessary to do in order to allow access.

I can bring interface up when logged as rood and using "ifconfig "

Any comment is welcome and thank you in advance,

Regards,

Elko

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2010-02-08  9:32 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-02-07  8:12 Selinux in enforcing mode prevent network interface to be configured at boot for Debian stable ( 5.0) Elko Kuric
2010-02-07  8:42 ` Justin P. Mattock
2010-02-07  9:31   ` Elko Kuric
2010-02-07  9:59     ` Justin P. Mattock
2010-02-07 16:23       ` Michal Svoboda
2010-02-07 17:24         ` Justin P. Mattock
2010-02-07 16:16 ` Michal Svoboda
2010-02-08  9:32   ` Elko Kuric

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.