Security Enhanced Linux
What's New
Frequently Asked Questions
Background
Documents
License
Download
Participating
Mail List
Archives
Remaining Work
Contributors
Related Work
Press Releases
Information Assurance Research
NIARL In-house Research Areas
Mathematical Sciences Program
Sabbaticals
Computer & Information Sciences Research
Technology Transfer
Advanced Computing
Advanced Mathematics
Communications & Networking
Information Processing
Microelectronics
Other Technologies
Technology Fact Sheets
Publications
Related Links
|
SELinux Mailing ListI can ' t use named on LSM-based Prototype. Why?
From: Yuichi Nakamura <ynakam_at_ori.hitachi-sk.co.jp>
Date: Tue, 25 Sep 2001 16:40:35 +0900
Named doesn't response to nslookup. I can use other services(httpd,sendmail,ftpd). And,Named works on usual Linux(2.4.3,2.4.9) and on original SELinux prototype. I installed SELinux (LSM-based Prototype) as development mode in RH7.1. And the kernel configration option is following, CONFIG_NETFILTER="Y" CONFIG_CAPABILITIES ="N" CONFIG_SELINUX="Y" CONFIG_LSM_IP="Y". The startup log of named is following. Sep 25 15:11:54 myhost named[797]: starting BIND 9.1.0 -u named Sep 25 15:11:54 myhost named[797]: using 1 CPU Sep 25 15:11:54 myhost named: named startup succeeded Sep 25 15:11:54 myhost named[801]: loading configuration from'/etc/named.conf' Sep 25 15:11:54 myhost named[801]: the default for the 'auth-nxdomain' option is now 'no' Sep 25 15:11:54 myhost named[801]: no IPv6 interfaces found Sep 25 15:11:54 myhost named[801]: listening on IPv4 interface lo, 127.0.0.1#53 Sep 25 15:11:54 myhost named[801]: could not listen on UDP socket: permission denied
Sep 25 15:11:54 myhost named[801]: creating IPv4 interface lo failed;
interface ignored
Sep 25 15:11:54 myhost named[801]: could not listen on UDP socket: permission denied
Sep 25 15:11:54 myhost named[801]: creating IPv4 interface eth0 failed;
interface ignored
Why named doesn't work on LSM based prototype? Did I miss kernel configuration or else? Please tell me. Yuichi Nakamura Hitachi Software Engineering Co.,Ltd. ynakam@ori.hitachi-sk.co.jp -- You have received this message because you are subscribed to the selinux list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.Received on Tue 25 Sep 2001 - 03:53:48 EDT |
|
Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009 |