Research Menu

.
Skip Search Box

SELinux Mailing List

Re: newrole failed in enforcing mode

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Wed, 17 Mar 2004 07:41:48 -0500


On Wed, 2004-03-17 at 06:27, Carsten Grohmann wrote:
> On Dienstag, 16. März 2004 19:13, Stephen Smalley wrote:
> > To debug the newrole failure in enforcing mode, do a 'make
> > enableaudit reload' in policy and then try using newrole, and
>
> "make enableaudit" was a good hint. The newrole domain needs read
> access to shadow_t. The attached patch grant this by using the auth
> attribute.

This should be handled by having pam_unix run the helper program when it cannot directly read /etc/shadow, and the helper program should run in a domain that can read /etc/shadow. Do you have the same problem with the latest pam package from the Fedora Core 2 development tree? The SRPMS from nsa.gov/selinux are a little old; I've hesitated to update them to the FC2 devel packages because some of those SRPMS wouldn't build or would fail regression tests for me on FC1 or even on FC2 test1.

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Wed 17 Mar 2004 - 07:42:28 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service