Displaying 2 results from an estimated 2 matches for "ldconfig_exec_t".
2015 Jan 19
2
CentOS-6.6 Fail2Ban and Postfix Selinux AVCs
I am seeing these in the log of one of our off-site NX hosts running
CentOS-6.6.
type=AVC msg=audit(1421683972.786:4372): avc: denied { create } for
pid=22788 comm="iptables" scontext=system_u:system_r:fail2ban_t:s0
tcontext=system_u:system_r:fail2ban_t:s0 tclass=rawip_socket
Was caused by:
Missing type enforcement (TE) allow rule.
You can use
2015 Jan 19
0
CentOS-6.6 Fail2Ban and Postfix Selinux AVCs
...ol
> # semodule -i mypol.pp
>
>
It appears that the starting date of these errors corresponds to the
day on which we first began to jail SSH attempts on that host.
We eventually ended up with a custom policy that looks like this:
#============= fail2ban_t ==============
allow fail2ban_t ldconfig_exec_t:file { read execute open getattr
execute_no_trans };
allow fail2ban_t insmod_exec_t:file { read execute open };
allow fail2ban_t self:capability { net_admin net_raw };
allow fail2ban_t self:rawip_socket { getopt create setopt };
allow fail2ban_t sysctl_kernel_t:dir search;
allow fail2ban_t sysctl_...