Results 1 to 2 of 2
hi
i m new to selinux. i have installed selinux on my ubuntu hardy8.04 machine. it installed successfully.
now i have created a new linux user and map this user ...
- 02-24-2009 #1Just Joined!
- Join Date
- Feb 2009
- Posts
- 1
selinux newuser problem
hi
i m new to selinux. i have installed selinux on my ubuntu hardy8.04 machine. it installed successfully.
now i have created a new linux user and map this user to selinux user using "semanage -a -s "staff_u" newusr" command.
when i run "semanage login -l" command it shows entry of newuser there.
now the problem is,when i restart the machine and use "newusr" for login to xsession it through me error "cannot start the session due to some internal error".as this time selinux is in "enforcing" mode. when i change the mnode to "permissive" then "neusr" is abel to login.
please suggest me if i m missing some steps there.
Errors:
=========================================
Feb 24 18:40:35 ists-desktop kernel: [ 43.408181] audit(1235481035.882:3): avc: denied { entrypoint } for pid=5551 comm="gdm" path="/etc/gdm/Xsession" dev=sda1 ino=3081327 scontext=staff_u:staff_r:staff_t tcontext=system_u:object_r:etc_t tclass=file
Feb 24 18:40:36 ists-desktop kernel: [ 43.916433] audit(1235481036.390:4): avc: denied { setattr } for pid=5551 comm="seahorse-agent" name="orbit-newusr" dev=sda1 ino=3833863 scontext=staff_u:staff_r:staff_t tcontext=system_u:object_r
dm_tmp_t tclass=dir
Feb 24 18:40:36 ists-desktop kernel: [ 44.383718] audit(1235481036.858:5): avc: denied { unlink } for pid=5659 comm="gconf-sanity-ch" name="linc-161b-0-5c61989ad21d3" dev=sda1 ino=3833876 scontext=staff_u:staff_r:staff_t tcontext=staff_u:object_r
dm_tmp_t tclass=sock_file
==========================================
Thanks
- 02-26-2009 #2
Please refrain from double posting, it's against the forum rules, continue the discussion in this thread only. Thank you and have a nice day.
I do not respond to private messages asking for Linux help, Please keep it on the forums only.
All new users please read this. and the Forum FAQS.


Reply With Quote
