Re: Selinux: /bin/su and pam_selinux
Luis Ressel <[email protected]> Sat, 21 Jan 2017 20:04:14 +0100
| Newsgroups | gmane.linux.gentoo.hardened |
|---|---|
| Message-ID | <[email protected]> |
On Sat, 21 Jan 2017 18:04:51 +0000 Robert Sharp <selinux-/[email protected]> wrote: > type=AVC msg=audit(1485020695.038:10368): avc: denied > { create } for pid=20374 comm="su" > scontext=staff_u:sysadm_r:sysadm_su_t tcontext=root:sysadm_r:sysadm_t > tclass=key permissive=1 I haven't looked at this in detail, so please forgive me if my answer is utter nonsense: Have you considered that this denial might be caused by UBAC (that's the fancy name for the restrictions refpolicy places upon interactions between different selinux users, staff_u and root in this case)? Anyway, personally I've never tried making su work with SELinux. "sudo -r sysadm_r -t sysadm_t" works like a charm. Regards, Luis Ressel
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEEBodceejG8DmqwH0BfuuULjDLicFAliDsK8ACgkQBfuuULjD Lif2rg/9G/YeYbzUaBu3tmZXwOj1CWea3DyTn3DQjQzdVfHqpW+zXBPetG/Qjn9m UBs+3jh8x8G7jIa2c3Ksf4DxtmZOPDxuk0mgX/GOfLbwPuN3MKTFsfHKOCEbCbpB C2/y51g43ihjsKwyJN1W3iZ8DiKgVS7Rl7H2GCQzGhfgBUcNyVe/gryt8oWdo0UQ Gh+Jiqn6otes51xyFcNdUQsOzzIfnMd7GvYF5x51HrAtIUPFHGhipscej56KeJ6f 1nmJLGftl1oJjDiijiF4MgJQwWeCMfVVE1y3iDxLZBtZO6PkMkWPr4KU+hVNjWo0 ldms9WoIL8iW1Q3vRfxTXBDb1U6QfIc4JYnie9MopDP2jCdOtorDgN5t+rSUdhtM iLrBJoJ29N9wegCKAuu+cUv+hkB9CFpRIbb6oK+JYmEcipmIdpS41/3MzTPwv3FK Twqw7sC9rt4FVJ94pQgVTr8O6FaKPza6QNd4Ak5zM/HdVNCtd+abtbBNVqlm7Y+i mPFByDlVlhoGLClZmQe2PgnPngdX444FLj1xwfcYiEtermWLwMtzXB+PTMohHogR cch+tiny7P5h7uRlITKA0i3VPPvpONI3F0WJh0CZkD3qdUG9JGT9C8UElLZqMeS3 sRYCg2U4gE4eJmSzzUoO6M5btSiPeuaKlpSF8I5vEV6BakYdXQM= =XRBH -----END PGP SIGNATURE-----