From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: krb5 issues Date: Thu, 26 May 2016 16:04:49 -0400 Message-ID: <5883713.JF5uphcy4a@x2> References: <57432011.1060201@kenbass.com> <5744603D.9020504@kenbass.com> <57471335.3010406@kenbass.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <57471335.3010406@kenbass.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com On Thursday, May 26, 2016 11:16:05 AM Ken Bass wrote: > On 05/24/2016 10:07 AM, Ken Bass wrote: > > On a related note, using krb5 causes a problem with selinux. Unless I > > disable it (or figure out a rule) auditd fails to start because it is > > denied permission to create /var/tmp/auditd_0 kerberos replay cache file. > > Is there a rule or procedure to properly fix that? > > Is there somewhere to file a bug report for this at? You could use Bugzilla and file against selinux-policy. > Obviously the selinux is not being setup for auditd to manage the > /var/tmp/auditd_0 file when krb5 is enabled. Using Centos 7.2. I think its used so rarely that no one has noticed. -Steve