External Commands not working

Marc Powell marc at ena.com
Thu Mar 17 20:43:34 CET 2005


[please don't top post if you can help it]

> -----Original Message-----
> From: nagios-users-admin at lists.sourceforge.net [mailto:nagios-users-
> admin at lists.sourceforge.net] On Behalf Of Scott Gwartney
> Sent: Thursday, March 17, 2005 12:58 PM
> To: nagios-users at lists.sourceforge.net
> Subject: RE: [Nagios-users] External Commands not working
> 
> I ran audit2allow -l -i /var/log/messages Restarted nagios and apache,
> tried
> external command and got the same error. The system message showed:
> 
> audit(1111085444.812:0): avc:  denied  { getattr } for  pid=7241
> exe=/usr/local/nagios/sbin/cmd.cgi
> path=/usr/local/nagios/var/rw/nagios.cmd
> dev=dm-0 ino=3591465 scontext=root:system_r:httpd_sys_script_t
> tcontext=root:object_r:usr_t tclass=fifo_file

Audit2allow doesn't actually change the policy. It just proposes a
change that you need to make manually. Did you add it to your policy
file then do a 'cd /etc/selinux/strict/src/policy; make load'? I believe
the policy file you need to edit might be located at
/etc/selinux/strict/src/policy/domains/misc/local.te but I would
encourage you to research SELinux on your own if you are not familiar
with it. Additionally, it is my understanding that audit2allow likely
proposes a policy change that may be more open than is required. Again,
research on your part based on your acceptable policies would be
warranted.

--
Marc




-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_ide95&alloc_id396&op=click
_______________________________________________
Nagios-users mailing list
Nagios-users at lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nagios-users
::: Please include Nagios version, plugin version (-v) and OS when reporting any issue. 
::: Messages without supporting info will risk being sent to /dev/null





More information about the Users mailing list