Re:Re: The relationship between SELinux and OpenPegasus

Ashok K Pathak <[email protected]> Wed, 19 Jun 2013 15:42:15 +0530
Newsgroups gmane.network.open-pegasus.general
Message-ID <OFB707DD6F.D52004CC-ON65257B8F.0037BB79-65257B8F.003827A2@in.ibm.com>
If you are creating a  new namespace(amespace named root/hpq), I think you
need to compile the appropriate CIM .mof files into the new namespace . For
instance , if anyone  needs to create classes that use the standard CIM
elements, compile the CIM Core Schema into the namespace. If the plan is to
create classes that extend the CIM Schema, compile the CIM Schema  into the
namespac( look into repository once  pegaus get build
pegasus/repository/test#TestProvider/classes,
pegasus/repository/root#cimv2/classes)

Also you can look into below pegsaus folder To get more how CIM class is
inherited and get compile/loaded/registered

pegasus/Schemas/Pegasus
     -Internal
     -InteroP
     -ManagedSystem


Regards
Ashok


                                                                           
             ff-bahamut                                                    
             <[email protected]                                             
             om>                                                        To 
                                       "Paul Robert Marino"                
             06/17/2013 08:09          <[email protected]>, "Devchandra  
             AM                        L Meetei" <[email protected]>,     
                                                                        cc 
                                       [email protected]           
                                                                   Subject 
                                       Re:Re: The relationship between     
                                       SELinux and OpenPegasus             
                                                                           
                                                                           
                                                                           
                                                                           
                                                                           
                                                                           




Thank you all, I got it.
I have another question:
By default, tog-Pegasus have already installed the core-cim under namespace
root/cimv2. I have created a new namespace named root/hpq, and I have my
own classes that inherit from the core-cim and need to be registered under
root/hpq. My question is do I have to re-register the core-cim under
root/hpq?


Thanks and Regards,
Bai, Bin.

At 2013-06-13 20:18:34,"Paul Robert Marino" <[email protected]> wrote:
  FYI
  I haven't had the time yet to recreate it on RHEL yet but yesterday on
  Scientific Linux 6.4 I! found an order of operations issue while
  installing openpegasus during a kickstart.
  Essentially what happens is it installs it before creating the user and
  the groups so  it errors and sets the file ownership to root:root
  instead. A simple yum reinstall of the package fixes it but it can cause
  problems if you are unaware of it.

  Also if you don't want to use selinux you should have it in permissive
  mode not disabled. Its a nightmare if you disabled it on install and want
  to enable it latter because none of the contexts get loaded if it is
  disabled. Also the audit log is a good way to figure out if you can turn
  it on without causing issues.



  -- Sent from my HP Pre3

  On Jun 13, 2013 1:48 AM, Devchandra L Meetei <[email protected]> wrote:

  As far as I believe, The SELinux policy/setting for pegasus is done by
  the RedHat.

  and yes, in one of my earlier projects we ended up shipping our own
  targeted policy to over come SELinux issues.

  May be You can try something at RedHat bugzilla.


  On Thu, Jun 13, 2013 at 10:54 AM, ff-bahamut <[email protected]> wrote:
   Hello All,

   I'm a developer for server manageability. Our software on RHEL is based
   on tog-peagsus. Right now, I was committed to improve the speed of
   installation of our product. I found that the installation is going to
   disable SELinux, which will take about 20 seconds. I'm trying to find
   out why it need to disable SELinux. From the following site

   https://wiki.opengroup.org/pegasus-wiki/doku.php?id=dev:release:rhel4u4_25_documentationitems

   My understanding is that if the SELinux policy is higher than 1.17.20,
   tog-pegasus can work fine with or without SELinux. Maybe the
   installation of our product is too old and ! forgot to update.
   I don't know if I'm right. If you have any other comments, could you
   please let me know?


   Thanks and Regards,
   Bai, Bin





  --
  Warm Regards
  --Dev
  OpenPegasus Developer/Committer

  (\__/)
  (='.'=) This is Bunny. Copy and paste bunny
  (")_(") to help him gain world domination.