Research Menu

.
Skip Search Box

SELinux Mailing List

Re: Problem Setting Policy To Enforcing Mode

From: Daniel J Walsh <dwalsh_at_redhat.com>
Date: Fri, 21 Nov 2008 14:41:02 -0500


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Rahul Jain wrote:
> Hi All,
>
> This is the first time I am writing to this mailing list in hope of receiving help. I am trying to port reference policy by tresys on Montavista. I am able to run the policy well in permmisive mode with no avc messages in audit log, kern.log or messages. But when I put the policy into enforcing mode my system fails to boot, reason seems to be problem with init process. I am not able to debug the problem because no avc messages are generated for the same, probably because the issue comes up even before logging deamons start. Is there anyway I can debug my policy and log the avc messages from the very beginning of the system startup.
>
> Rahul Jain
> Rahul Jain
>
>
>

AVC Messages should come to the screen.

Try semodule -DB to turn off dontaudit rules.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkknDs4ACgkQrlYvE4MpobMW1wCfXWKS0t678aMoumM3izMLMhEk RPEAn25rhlfbw8Opq3FZymzRsUKsShFi
=DlJu
-----END PGP SIGNATURE-----

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 21 Nov 2008 - 14:41:10 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service