Gentoo Archives: gentoo-hardened

From: Markus Bartl <hardened@××××××××××××××××.de>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] /etc/init.d/dhcpd start -> error
Date: Mon, 06 Oct 2008 20:48:45
Message-Id: 48EA79A5.40805@noack-ingenieure.de
In Reply to: Re: [gentoo-hardened] /etc/init.d/dhcpd start -> error by Roman Fulop
1 Hi Roman.
2
3 That did it. Thanks.
4 Could anybody explain what happened there?
5 Thanks.
6
7 Markus
8
9 Roman Fulop schrieb:
10 > Hi,
11 >
12 > I had problem running chrooted dhcp 3.1.1 with
13 > CONFIG_GRKERNSEC_CHROOT_CAPS set. Try disabling it via sysctl or procfs.
14 >
15 > Roman
16 >
17 > Markus Bartl wrote:
18 >
19 >> brant williams schrieb:
20 >>
21 >> Did you enable any chroot restrictions in the kernel config?
22 >>
23 >>
24 >> brant williams
25 >> FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002
26 >>
27 >>
28 >>
29 >> On Mon, 6 Oct 2008, Markus Bartl wrote:
30 >>
31 >>
32 >>>>> Date: Mon, 06 Oct 2008 17:04:15 +0200
33 >>>>> From: Markus Bartl <hardened@××××××××××××××××.de>
34 >>>>> Reply-To: gentoo-hardened@l.g.o
35 >>>>> To: gentoo-hardened@l.g.o
36 >>>>> Subject: [gentoo-hardened] /etc/init.d/dhcpd start -> error
37 >>>>>
38 >>>>> Hi there.
39 >>>>>
40 >>>>> I did a fresh installation with hardened-sources 2.6.25-r7 with pax
41 >>>>> and grsec (server) enabled.
42 >>>>> After installing dhcpd with configuration to chroot - environment I
43 >>>>> get the following errors in /var/log/debug:
44 >>>>>
45 >>>>> Oct 6 16:54:35 odin dhcpd: unable to create icmp socket: Operation
46 >>>>> not permitted
47 >>>>> ...
48 >>>>> Oct 6 16:54:35 odin dhcpd: Open a socket for LPF: Operation not
49 >>>>> permitted
50 >>>>>
51 >>>>> /var/log/grsec.log doesnt contain any hints.
52 >>>>>
53 >>>>> Any idea would be welcome.
54 >>>>>
55 >>>>> Kind regards,
56 >>>>> Markus
57 >>>>>
58 >>>>>
59 >>>>>
60 >>>>>
61 >> Hi brant.
62 >>
63 >
64 >
65 >> Yes. chroot restrictions are set and no, socket restrictions are not set.
66 >> Thanks in advance.
67 >>
68 >
69 >
70 >> Markus.
71 >>
72 >
73 >
74 >