CentOS-6.5 OpenDKIM-2.9.0 (epel) Postfix-2.6.6 (updates) I am trying to get opendkim working with our mailing lists. In the course of that endeavour I note that these messages are appearing in our syslog: May 4 20:50:02 inet08 setroubleshoot: SELinux is preventing /usr/sbin/opendkim from using the signull access on a process. For complete SELinux messages. run sealert -l 442cb257-3db2-488c-a92e-bfc936e16a0c May 4 20:55:25 inet08 setroubleshoot: SELinux is preventing /usr/sbin/opendkim from using the dac_override capability. For complete SELinux messages. run sealert -l c7c1199d-008d-4ae5-b61f-71a11edb0aa3 May 5 04:03:57 inet08 setroubleshoot: SELinux is preventing /usr/sbin/opendkim from search access on the directory /sys. For complete SELinux messages. run sealert -l 800523d5-0420-4038-9c7d-c2ec47c3bb6a Anyone have any guidance to e on as to what this means and how I get rid of it, besides generating a custom policy I mean. -- *** E-Mail is NOT a SECURE channel *** James B. Byrne mailto:ByrneJB at Harte-Lyne.ca Harte & Lyne Limited http://www.harte-lyne.ca 9 Brockley Drive vox: +1 905 561 1241 Hamilton, Ontario fax: +1 905 561 0757 Canada L8E 3C3
On 05.05.2014 16:22, James B. Byrne wrote:> CentOS-6.5 > OpenDKIM-2.9.0 (epel) > Postfix-2.6.6 (updates) > > I am trying to get opendkim working with our mailing lists. In the > course of > that endeavour I note that these messages are appearing in our syslog: > > > May 4 20:50:02 inet08 setroubleshoot: SELinux is preventing > /usr/sbin/opendkim from using the signull access on a process. For > complete > SELinux messages. run sealert -l 442cb257-3db2-488c-a92e-bfc936e16a0c > > May 4 20:55:25 inet08 setroubleshoot: SELinux is preventing > /usr/sbin/opendkim from using the dac_override capability. For > complete > SELinux messages. run sealert -l c7c1199d-008d-4ae5-b61f-71a11edb0aa3 > > May 5 04:03:57 inet08 setroubleshoot: SELinux is preventing > /usr/sbin/opendkim from search access on the directory /sys. For > complete > SELinux messages. run sealert -l 800523d5-0420-4038-9c7d-c2ec47c3bb6a > > > > Anyone have any guidance to e on as to what this means and how I get > rid of > it, besides generating a custom policy I mean.I would try to contact the EPEL ml or open a issue in redhat's bugzilla. Lucian -- Sent from the Delta quadrant using Borg technology! Nux! www.nux.ro
On 05/05/2014 11:22 AM, James B. Byrne wrote:> CentOS-6.5 > OpenDKIM-2.9.0 (epel) > Postfix-2.6.6 (updates) > > I am trying to get opendkim working with our mailing lists. In the course of > that endeavour I note that these messages are appearing in our syslog: > > > May 4 20:50:02 inet08 setroubleshoot: SELinux is preventing > /usr/sbin/opendkim from using the signull access on a process. For complete > SELinux messages. run sealert -l 442cb257-3db2-488c-a92e-bfc936e16a0c > > May 4 20:55:25 inet08 setroubleshoot: SELinux is preventing > /usr/sbin/opendkim from using the dac_override capability. For complete > SELinux messages. run sealert -l c7c1199d-008d-4ae5-b61f-71a11edb0aa3 > > May 5 04:03:57 inet08 setroubleshoot: SELinux is preventing > /usr/sbin/opendkim from search access on the directory /sys. For complete > SELinux messages. run sealert -l 800523d5-0420-4038-9c7d-c2ec47c3bb6a > > > > Anyone have any guidance to e on as to what this means and how I get rid of > it, besides generating a custom policy I mean. >Attaching the output of the sealert command or the audit.log would help.