On Mon, 9 Jan 2017 10:55:05 +0100 Sumit wrote: SB> There are older reports that a similar audit message was triggered by SB> wrong SELinux labels on $HOME/.ssh and the files within. Although none SB> of the typical files in this directory are needed by GSSAPI SB> authentication it might worth to check. Does authentication work if you SB> temporally disable SELinux by calling 'setenforce 0' as root on the SB> command line?
Or instead of disabling, fix the labels restorecon -rv ~/.ssh With -v restorecon will report if it changed any labels. or check for actual denials grep avc /var/log/audit/audit.log | grep ssh Robert -- Senior Software Engineer @ Parsons
pgpjym51Kq_KZ.pgp
Description: OpenPGP digital signature
-- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project