Gentoo Archives: gentoo-hardened

From: Roman Fulop <ml@××××××××××××××.sk>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] /etc/init.d/dhcpd start -> error
Date: Mon, 06 Oct 2008 16:06:16
Message-Id: 48EA377E.9000102@ensof1.trithem.sk
In Reply to: Re: [gentoo-hardened] /etc/init.d/dhcpd start -> error by Markus Bartl
1 Hi,
2
3 I had problem running chrooted dhcp 3.1.1 with
4 CONFIG_GRKERNSEC_CHROOT_CAPS set. Try disabling it via sysctl or procfs.
5
6 Roman
7
8 Markus Bartl wrote:
9 > brant williams schrieb:
10 >
11 > Did you enable any chroot restrictions in the kernel config?
12 >
13 >
14 > brant williams
15 > FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002
16 >
17 >
18 >
19 > On Mon, 6 Oct 2008, Markus Bartl wrote:
20 >
21 >>>> Date: Mon, 06 Oct 2008 17:04:15 +0200
22 >>>> From: Markus Bartl <hardened@××××××××××××××××.de>
23 >>>> Reply-To: gentoo-hardened@l.g.o
24 >>>> To: gentoo-hardened@l.g.o
25 >>>> Subject: [gentoo-hardened] /etc/init.d/dhcpd start -> error
26 >>>>
27 >>>> Hi there.
28 >>>>
29 >>>> I did a fresh installation with hardened-sources 2.6.25-r7 with pax
30 >>>> and grsec (server) enabled.
31 >>>> After installing dhcpd with configuration to chroot - environment I
32 >>>> get the following errors in /var/log/debug:
33 >>>>
34 >>>> Oct 6 16:54:35 odin dhcpd: unable to create icmp socket: Operation
35 >>>> not permitted
36 >>>> ...
37 >>>> Oct 6 16:54:35 odin dhcpd: Open a socket for LPF: Operation not
38 >>>> permitted
39 >>>>
40 >>>> /var/log/grsec.log doesnt contain any hints.
41 >>>>
42 >>>> Any idea would be welcome.
43 >>>>
44 >>>> Kind regards,
45 >>>> Markus
46 >>>>
47 >>>>
48 >>>>
49 > Hi brant.
50
51 > Yes. chroot restrictions are set and no, socket restrictions are not set.
52 > Thanks in advance.
53
54 > Markus.

Replies

Subject Author
Re: [gentoo-hardened] /etc/init.d/dhcpd start -> error Markus Bartl <hardened@××××××××××××××××.de>