Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Paulo Cavalcanti
On Wed, Jan 12, 2011 at 7:07 PM, Daniel J Walsh dwa...@redhat.com wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/12/2011 04:03 PM, Paul Howarth wrote: On Wed, 12 Jan 2011 13:02:21 -0500 Daniel J Walsh dwa...@redhat.com wrote: On 01/12/2011 06:29 AM, Paulo Cavalcanti wrote:

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Paulo Cavalcanti
On Thu, Jan 13, 2011 at 8:02 AM, Paulo Cavalcanti pro...@gmail.com wrote: On Wed, Jan 12, 2011 at 7:07 PM, Daniel J Walsh dwa...@redhat.com wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/12/2011 04:03 PM, Paul Howarth wrote: On Wed, 12 Jan 2011 13:02:21 -0500 Daniel J

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Wed, 2011-01-12 at 21:03 +, Paul Howarth wrote: On Wed, 12 Jan 2011 13:02:21 -0500 Daniel J Walsh dwa...@redhat.com wrote: On 01/12/2011 06:29 AM, Paulo Cavalcanti wrote: Hi, I have two HDs on my computer: one with rhel5 5.5 and the other with fedora 14. Both systems

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Thu, 2011-01-13 at 08:02 -0200, Paulo Cavalcanti wrote: On Wed, Jan 12, 2011 at 7:07 PM, Daniel J Walsh dwa...@redhat.com wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/12/2011 04:03 PM, Paul Howarth wrote: On

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Thu, 2011-01-13 at 08:14 -0500, Stephen Smalley wrote: On Wed, 2011-01-12 at 21:03 +, Paul Howarth wrote: On Wed, 12 Jan 2011 13:02:21 -0500 Daniel J Walsh dwa...@redhat.com wrote: On 01/12/2011 06:29 AM, Paulo Cavalcanti wrote: Hi, I have two HDs on my computer: one

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Paulo Cavalcanti
On Thu, Jan 13, 2011 at 11:28 AM, Stephen Smalley s...@tycho.nsa.gov wrote: On Thu, 2011-01-13 at 08:14 -0500, Stephen Smalley wrote: On Wed, 2011-01-12 at 21:03 +, Paul Howarth wrote: On Wed, 12 Jan 2011 13:02:21 -0500 Daniel J Walsh dwa...@redhat.com wrote: On 01/12/2011 06:29

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Thu, 2011-01-13 at 11:51 -0200, Paulo Cavalcanti wrote: Here it goes: type=SYSCALL msg=audit(01/13/2011 07:31:09.287:39) : arch=x86_64 syscall=lstat success=no exit=-13(Permission denied) a0=7ff594509d50 a1=73924c40 a2=73924c40 a3=2f534d50522f6c6d items=0 ppid=2230

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Thu, 2011-01-13 at 11:51 -0200, Paulo Cavalcanti wrote: On Thu, Jan 13, 2011 at 11:28 AM, Stephen Smalley s...@tycho.nsa.gov wrote: On Thu, 2011-01-13 at 08:14 -0500, Stephen Smalley wrote: On Wed, 2011-01-12 at 21:03 +, Paul Howarth wrote: On

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Stephen Smalley
On Thu, 2011-01-13 at 09:12 -0500, Stephen Smalley wrote: On Thu, 2011-01-13 at 11:51 -0200, Paulo Cavalcanti wrote: Here it goes: type=SYSCALL msg=audit(01/13/2011 07:31:09.287:39) : arch=x86_64 syscall=lstat success=no exit=-13(Permission denied) a0=7ff594509d50

Re: selinux: rhel5 x fedora 14

2011-01-13 Thread Paulo Cavalcanti
On Thu, Jan 13, 2011 at 12:47 PM, Stephen Smalley s...@tycho.nsa.gov wrote: On Thu, 2011-01-13 at 09:12 -0500, Stephen Smalley wrote: On Thu, 2011-01-13 at 11:51 -0200, Paulo Cavalcanti wrote: Here it goes: type=SYSCALL msg=audit(01/13/2011 07:31:09.287:39) : arch=x86_64

selinux: rhel5 x fedora 14

2011-01-12 Thread Paulo Cavalcanti
Hi, I have two HDs on my computer: one with rhel5 5.5 and the other with fedora 14. Both systems share some directories located in a common /home, mainly used by the httpd process. The problem is that selinux in fedora 14 uses unrestricted_u by default for all users, which rel5 does not

Re: selinux: rhel5 x fedora 14

2011-01-12 Thread Stephen Smalley
On Wed, 2011-01-12 at 09:29 -0200, Paulo Cavalcanti wrote: Hi, I have two HDs on my computer: one with rhel5 5.5 and the other with fedora 14. Both systems share some directories located in a common /home, mainly used by the httpd process. The problem is that selinux in fedora 14 uses

Re: selinux: rhel5 x fedora 14

2011-01-12 Thread Paul Howarth
On Wed, 12 Jan 2011 13:02:21 -0500 Daniel J Walsh dwa...@redhat.com wrote: On 01/12/2011 06:29 AM, Paulo Cavalcanti wrote: Hi, I have two HDs on my computer: one with rhel5 5.5 and the other with fedora 14. Both systems share some directories located in a common /home, mainly used by

Re: selinux: rhel5 x fedora 14

2011-01-12 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/12/2011 04:03 PM, Paul Howarth wrote: On Wed, 12 Jan 2011 13:02:21 -0500 Daniel J Walsh dwa...@redhat.com wrote: On 01/12/2011 06:29 AM, Paulo Cavalcanti wrote: Hi, I have two HDs on my computer: one with rhel5 5.5 and the other with