SELinux blocking nagios' cgis on FC5
Chris Stankaitis
chris.stankaitis at datawire.net
Fri Jun 23 16:58:10 CEST 2006
> audit(1151073510.912:1650): avc: denied { read } for pid=7942
> comm="status.cgi" name="objects.cache" dev=dm-0 ino=98630
> scontext=root:system_r:httpd_sys_script_t:s0
> tcontext=root:object_r:var_log_t:s0 tclass=file
> audit(1151073601.054:1651): avc: denied { read } for pid=7999
> comm="status.cgi" name="objects.cache" dev=dm-0 ino=98630
> scontext=root:system_r:httpd_sys_script_t:s0
> tcontext=root:object_r:var_log_t:s0 tclass=file
> audit(1151073696.660:1652): avc: denied { read } for pid=8037
> comm="status.cgi" name="objects.cache" dev=dm-0 ino=98630
> scontext=root:system_r:httpd_sys_script_t:s0
> tcontext=root:object_r:var_log_t:s0 tclass=file
> audit(1151073787.393:1653): avc: denied { read } for pid=8067
> comm="status.cgi" name="objects.cache" dev=dm-0 ino=98630
> scontext=root:system_r:httpd_sys_script_t:s0
> tcontext=root:object_r:var_log_t:s0 tclass=file
> audit(1151073877.523:1654): avc: denied { read } for pid=8108
> comm="status.cgi" name="objects.cache" dev=dm-0 ino=98630
> scontext=root:system_r:httpd_sys_script_t:s0
> tcontext=root:object_r:var_log_t:s0 tclass=file
> audit(1151073967.653:1655): avc: denied { read } for pid=8203
> comm="status.cgi" name="objects.cache" dev=dm-0 ino=98630
> scontext=root:system_r:httpd_sys_script_t:s0
> tcontext=root:object_r:var_log_t:s0 tclass=file
>
>
what's the context on /var/log/nagios... I am no expert but it looks
like status.cgi is not allowed (by SELinux) to read the objects.cache
--Chris
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
_______________________________________________
Nagios-users mailing list
Nagios-users at lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nagios-users
::: Please include Nagios version, plugin version (-v) and OS when reporting any issue.
::: Messages without supporting info will risk being sent to /dev/null
More information about the Users
mailing list