* MLS Enforcing Problem @ 2016-08-26 9:44 Kashif ali 2016-08-26 16:48 ` ileyd 0 siblings, 1 reply; 5+ messages in thread From: Kashif ali @ 2016-08-26 9:44 UTC (permalink / raw) To: SELinux; +Cc: sds [-- Attachment #1: Type: text/plain, Size: 256 bytes --] Hi * I'm facing an issue which is as follow When Selinux is in enforcing mode and Policy type is Mls after relabeling of whole system it doesn't Allow me to login it gives me error login incorrect did i missing something? or it is something else. Thanks [-- Attachment #2: Type: text/html, Size: 298 bytes --] ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: MLS Enforcing Problem 2016-08-26 9:44 MLS Enforcing Problem Kashif ali @ 2016-08-26 16:48 ` ileyd 2016-08-26 16:55 ` Kashif ali 0 siblings, 1 reply; 5+ messages in thread From: ileyd @ 2016-08-26 16:48 UTC (permalink / raw) To: Kashif ali, selinux Hi, Could you give more detail? What operating system are you running, what error message exactly are you getting, etc. This sounds vaguely like an issue that seems to be present on EL7 and later, and all remotely recent fedora versions. The issue seems to be caused by /etc being labelled as SystemHigh instead of SystemLow, despite the policy. If you start the system in permissive mode, relabel it manually, and then put in in enforcing mode, you're able to login, etc. I'm not sure what causes it or how to fix it. Kind Regards, ileyd > On 26 Aug 2016, at 7:44 PM, Kashif ali <kashif.ali.9498@gmail.com> wrote: > > Hi > * I'm facing an issue which is as follow > When Selinux is in enforcing mode and Policy type is Mls after relabeling of whole system it doesn't Allow me to login it gives me error login incorrect did i missing something? or it is something else. > Thanks > _______________________________________________ > Selinux mailing list > Selinux@tycho.nsa.gov > To unsubscribe, send email to Selinux-leave@tycho.nsa.gov. > To get help, send an email containing "help" to Selinux-request@tycho.nsa.gov. ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: MLS Enforcing Problem 2016-08-26 16:48 ` ileyd @ 2016-08-26 16:55 ` Kashif ali 2016-08-30 12:24 ` Simon Sekidde 0 siblings, 1 reply; 5+ messages in thread From: Kashif ali @ 2016-08-26 16:55 UTC (permalink / raw) To: ileyd; +Cc: SELinux [-- Attachment #1: Type: text/plain, Size: 1363 bytes --] i'm using centos 6.5 and there is no error after putting selinux in enforced machine won't allow me to login On Fri, Aug 26, 2016 at 9:48 PM, ileyd <ileyd@icloud.com> wrote: > Hi, > > Could you give more detail? What operating system are you running, what > error message exactly are you getting, etc. > > This sounds vaguely like an issue that seems to be present on EL7 and > later, and all remotely recent fedora versions. > > The issue seems to be caused by /etc being labelled as SystemHigh instead > of SystemLow, despite the policy. If you start the system in permissive > mode, relabel it manually, and then put in in enforcing mode, you're able > to login, etc. I'm not sure what causes it or how to fix it. > > Kind Regards, > ileyd > > > On 26 Aug 2016, at 7:44 PM, Kashif ali <kashif.ali.9498@gmail.com> > wrote: > > > > Hi > > * I'm facing an issue which is as follow > > When Selinux is in enforcing mode and Policy type is Mls after > relabeling of whole system it doesn't Allow me to login it gives me error > login incorrect did i missing something? or it is something else. > > Thanks > > _______________________________________________ > > Selinux mailing list > > Selinux@tycho.nsa.gov > > To unsubscribe, send email to Selinux-leave@tycho.nsa.gov. > > To get help, send an email containing "help" to > Selinux-request@tycho.nsa.gov. > [-- Attachment #2: Type: text/html, Size: 2013 bytes --] ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: MLS Enforcing Problem 2016-08-26 16:55 ` Kashif ali @ 2016-08-30 12:24 ` Simon Sekidde [not found] ` <CAFC8oaes9Sfq1KNbNYKJDDOtxEarSFb6Hk+Fs8FzmtzaK7y4Jg@mail.gmail.com> 0 siblings, 1 reply; 5+ messages in thread From: Simon Sekidde @ 2016-08-30 12:24 UTC (permalink / raw) To: Kashif ali; +Cc: ileyd, SELinux ----- Original Message ----- > From: "Kashif ali" <kashif.ali.9498@gmail.com> > To: "ileyd" <ileyd@icloud.com> > Cc: "SELinux" <selinux@tycho.nsa.gov> > Sent: Friday, August 26, 2016 12:55:56 PM > Subject: Re: MLS Enforcing Problem > > i'm using centos 6.5 and there is no error after putting selinux in enforced > machine won't allow me to login > How are you trying to login? Is this through ssh? If so please make sure you have the 'ssh_sysadm_login' boolean enabled. > On Fri, Aug 26, 2016 at 9:48 PM, ileyd < ileyd@icloud.com > wrote: > > > Hi, > > Could you give more detail? What operating system are you running, what error > message exactly are you getting, etc. > > This sounds vaguely like an issue that seems to be present on EL7 and later, > and all remotely recent fedora versions. > > The issue seems to be caused by /etc being labelled as SystemHigh instead of > SystemLow, despite the policy. If you start the system in permissive mode, > relabel it manually, and then put in in enforcing mode, you're able to > login, etc. I'm not sure what causes it or how to fix it. > > Kind Regards, > ileyd > > > On 26 Aug 2016, at 7:44 PM, Kashif ali < kashif.ali.9498@gmail.com > wrote: > > > > Hi > > * I'm facing an issue which is as follow > > When Selinux is in enforcing mode and Policy type is Mls after relabeling > > of whole system it doesn't Allow me to login it gives me error login > > incorrect did i missing something? or it is something else. > > Thanks > > _______________________________________________ > > Selinux mailing list > > Selinux@tycho.nsa.gov > > To unsubscribe, send email to Selinux-leave@tycho.nsa.gov . > > To get help, send an email containing "help" to > > Selinux-request@tycho.nsa.gov . > > > _______________________________________________ > Selinux mailing list > Selinux@tycho.nsa.gov > To unsubscribe, send email to Selinux-leave@tycho.nsa.gov. > To get help, send an email containing "help" to > Selinux-request@tycho.nsa.gov. -- Simon Sekidde * Red Hat, Inc. * Westford, MA gpg: 5848 958E 73BA 04D3 7C06 F096 1BA1 2DBF 94BC 377E ^ permalink raw reply [flat|nested] 5+ messages in thread
[parent not found: <CAFC8oaes9Sfq1KNbNYKJDDOtxEarSFb6Hk+Fs8FzmtzaK7y4Jg@mail.gmail.com>]
* Re: MLS Enforcing Problem [not found] ` <CAFC8oaes9Sfq1KNbNYKJDDOtxEarSFb6Hk+Fs8FzmtzaK7y4Jg@mail.gmail.com> @ 2016-08-30 12:27 ` Kashif ali 0 siblings, 0 replies; 5+ messages in thread From: Kashif ali @ 2016-08-30 12:27 UTC (permalink / raw) To: Simon Sekidde; +Cc: SELinux, ileyd [-- Attachment #1: Type: text/plain, Size: 2245 bytes --] No i am not login through ssh, i am try to directly login on machine and it gives error On 30 Aug 2016 5:24 pm, "Simon Sekidde" <ssekidde@redhat.com> wrote: ----- Original Message ----- > From: "Kashif ali" <kashif.ali.9498@gmail.com> > To: "ileyd" <ileyd@icloud.com> > Cc: "SELinux" <selinux@tycho.nsa.gov> > Sent: Friday, August 26, 2016 12:55:56 PM > Subject: Re: MLS Enforcing Problem > > i'm using centos 6.5 and there is no error after putting selinux in enforced > machine won't allow me to login > How are you trying to login? Is this through ssh? If so please make sure you have the 'ssh_sysadm_login' boolean enabled. > On Fri, Aug 26, 2016 at 9:48 PM, ileyd < ileyd@icloud.com > wrote: > > > Hi, > > Could you give more detail? What operating system are you running, what error > message exactly are you getting, etc. > > This sounds vaguely like an issue that seems to be present on EL7 and later, > and all remotely recent fedora versions. > > The issue seems to be caused by /etc being labelled as SystemHigh instead of > SystemLow, despite the policy. If you start the system in permissive mode, > relabel it manually, and then put in in enforcing mode, you're able to > login, etc. I'm not sure what causes it or how to fix it. > > Kind Regards, > ileyd > > > On 26 Aug 2016, at 7:44 PM, Kashif ali < kashif.ali.9498@gmail.com > wrote: > > > > Hi > > * I'm facing an issue which is as follow > > When Selinux is in enforcing mode and Policy type is Mls after relabeling > > of whole system it doesn't Allow me to login it gives me error login > > incorrect did i missing something? or it is something else. > > Thanks > > _______________________________________________ > > Selinux mailing list > > Selinux@tycho.nsa.gov > > To unsubscribe, send email to Selinux-leave@tycho.nsa.gov . > > To get help, send an email containing "help" to > > Selinux-request@tycho.nsa.gov . > > > _______________________________________________ > Selinux mailing list > Selinux@tycho.nsa.gov > To unsubscribe, send email to Selinux-leave@tycho.nsa.gov. > To get help, send an email containing "help" to > Selinux-request@tycho.nsa.gov. -- Simon Sekidde * Red Hat, Inc. * Westford, MA gpg: 5848 958E 73BA 04D3 7C06 F096 1BA1 2DBF 94BC 377E [-- Attachment #2: Type: text/html, Size: 3738 bytes --] ^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2016-08-30 12:27 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-08-26 9:44 MLS Enforcing Problem Kashif ali
2016-08-26 16:48 ` ileyd
2016-08-26 16:55 ` Kashif ali
2016-08-30 12:24 ` Simon Sekidde
[not found] ` <CAFC8oaes9Sfq1KNbNYKJDDOtxEarSFb6Hk+Fs8FzmtzaK7y4Jg@mail.gmail.com>
2016-08-30 12:27 ` Kashif ali
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.