Welcome to Linux Forums! With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.
Write an article for LinuxForums Today! Win Great Prizes!
Find the answer to your Linux question:
New to Linux Forums? Register here for free!
    Linux Forums > GNU Linux Zone > Linux Security > selinux newuser problem

Forgot Password?
 Linux Security   Discussion about keeping your machines secure, and the crackers out.

Site Navigation
Linux Articles
Linux Forums
Linux Downloads
Linux Hosting
Free Magazines
Job Board
IRC Chat
RSS Feeds
Linux Forum Topics
Linux Forums
Your Distro
Linux Resources
GNU Linux Zone
The Community
Reply
 
Thread Tools Display Modes
Old 02-24-2009   #1 (permalink)
Just Joined!
 
Join Date: Feb 2009
Posts: 1
selinux newuser problem

hi
i m new to selinux. i have installed selinux on my ubuntu hardy8.04 machine. it installed successfully.
now i have created a new linux user and map this user to selinux user using "semanage -a -s "staff_u" newusr" command.
when i run "semanage login -l" command it shows entry of newuser there.
now the problem is,when i restart the machine and use "newusr" for login to xsession it through me error "cannot start the session due to some internal error".as this time selinux is in "enforcing" mode. when i change the mnode to "permissive" then "neusr" is abel to login.
please suggest me if i m missing some steps there.

Errors:
=========================================
Feb 24 18:40:35 ists-desktop kernel: [ 43.408181] audit(1235481035.882:3): avc: denied { entrypoint } for pid=5551 comm="gdm" path="/etc/gdm/Xsession" dev=sda1 ino=3081327 scontext=staff_u:staff_r:staff_t tcontext=system_u:object_r:etc_t tclass=file

Feb 24 18:40:36 ists-desktop kernel: [ 43.916433] audit(1235481036.390:4): avc: denied { setattr } for pid=5551 comm="seahorse-agent" name="orbit-newusr" dev=sda1 ino=3833863 scontext=staff_u:staff_r:staff_t tcontext=system_u:object_rdm_tmp_t tclass=dir

Feb 24 18:40:36 ists-desktop kernel: [ 44.383718] audit(1235481036.858:5): avc: denied { unlink } for pid=5659 comm="gconf-sanity-ch" name="linc-161b-0-5c61989ad21d3" dev=sda1 ino=3833876 scontext=staff_u:staff_r:staff_t tcontext=staff_u:object_rdm_tmp_t tclass=sock_file
==========================================

Thanks
fileuploadoct08 is offline  



Reply With Quote
Old 02-26-2009   #2 (permalink)
Trusted Penguin
 
MikeTbob's Avatar
 
Join Date: Apr 2006
Location: Panther City, Tx
Posts: 4,471
Please refrain from double posting, it's against the forum rules, continue the discussion in this thread only. Thank you and have a nice day.
__________________
I do not respond to private messages asking for help.
Please keep it on the forums only.
MikeTbob is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Free Magazines
A Newbie's Getting Started Guide to Linux
Learn the basics of the Linux operating systems. Get to know what it is all about, and familiarize yourself with the practical side. Basically, if you're a complete Linux newbie and looking for a quick and easy guide to get you started this is it.
subscribe
Run Your Own Web Server Using Linux & Apache - Free 191 Page Preview
Learn about everything you'll need to build and maintain your Linux servers, and to deploy Web applications to them.
subscribe
Open Source Security Myths Dispelled
Dispel the five major myths surrounding Open Source Security and gain the tools necessary to make a truly informed decision for your IT organization
subscribe
InformationWeek
InformationWeek is the only newsweekly you'll need to stay on top of the latest developments in information technology.
subscribe



All times are GMT. The time now is 07:56 PM.






© 2000 - - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.3.1