Gentoo Archives: gentoo-hardened

From: Matt Harrison <iwasinnamuknow@×××××××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] locked out of selinux
Date: Mon, 29 Sep 2008 18:59:48
Message-Id: 48E12613.8090508@genestate.com
In Reply to: Re: [gentoo-hardened] [SOLVED] locked out of selinux by Matt Harrison
1 Matt Harrison wrote:
2 > Markus Bartl wrote:
3 >> I know this wont help, but i got exactly the same issue.
4 >> If i try to boot in enforcing mode, init is blocked and the boot sequence stops.
5 >> My build.conf looks exactly the same as Matts.
6 >> Any ideas would be really welcome. I really want to give SELinux a chance, but
7 >> things get lost in the basics :-(
8 >>
9 >> Regards,
10 >> Markus
11 >
12 > Boy is my face red, well it seems that all the problems were due to the
13 > fact I hadn't merged the new config files after installing everything.
14 >
15 > I believe /etc/pam.d/login was to blame, after merging the changes for
16 > it I can now login and work with enforce enabled.
17 >
18 > Sorry that I bothered the list with such a silly problem but hopefully
19 > others won't make this mistake (or they'll know how to fix it now).
20 >
21 > Thanks for all the input.
22 >
23 > Matt
24 >
25
26 Nearly solved anyway, now the pam/login file is fixed logins work and
27 shell commands are ok.
28
29 The problem now is that courier-* services always give permission
30 denied, possibly because they're running in what appears to be the wrong
31 context.
32
33 Also, the system still doesn't boot, I have to boot in permissive then
34 set enforced after boot.
35
36 Thanks
37
38 Matt