From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ken Bass Subject: Re: krb5 issues Date: Thu, 26 May 2016 11:16:05 -0400 Message-ID: <57471335.3010406@kenbass.com> References: <57432011.1060201@kenbass.com> <5744603D.9020504@kenbass.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; Format="flowed" Content-Transfer-Encoding: 7bit Return-path: Received: from mx1.redhat.com (ext-mx01.extmail.prod.ext.phx2.redhat.com [10.5.110.25]) by int-mx10.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP id u4QFG8ov012217 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for ; Thu, 26 May 2016 11:16:08 -0400 Received: from mail.kenbass.com (kenbass.com [216.127.139.130]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id B98877F6A7 for ; Thu, 26 May 2016 15:16:07 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by mail.kenbass.com (Postfix) with ESMTP id AB99140C for ; Thu, 26 May 2016 11:16:06 -0400 (EDT) Received: from mail.kenbass.com ([127.0.0.1]) by localhost (mail.kenbass.com [127.0.0.1]) (amavisd-new, port 10026) with LMTP id Xcsjkle8KKg0 for ; Thu, 26 May 2016 11:16:06 -0400 (EDT) In-Reply-To: <5744603D.9020504@kenbass.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com On 05/24/2016 10:07 AM, Ken Bass wrote: > > On a related note, using krb5 causes a problem with selinux. Unless I > disable it (or figure out a rule) auditd fails to start because it is > denied permission to create /var/tmp/auditd_0 kerberos replay cache file. > Is there a rule or procedure to properly fix that? Is there somewhere to file a bug report for this at? Obviously the selinux is not being setup for auditd to manage the /var/tmp/auditd_0 file when krb5 is enabled. Using Centos 7.2.