Gentoo Archives: gentoo-hardened

From: Matt Harrison <iwasinnamuknow@×××××××××.com>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] locked out of selinux
Date: Fri, 26 Sep 2008 15:18:14
Message-Id: 48DCFD52.9050802@genestate.com
1 Hi all,
2
3 I've recently converted one of our firewall/router/proxies to a hardened
4 system.
5
6 I changed the profile, rebuilt a kernel with selinux and recompiled all
7 necessary packages.
8
9 Everything seems to be ok until I set enforcing mode to on, then I get
10 locked out of everything:
11
12 permission denied on many binaries, ls, cat, echo etc.
13 permission on some directories ie, /root missing.
14 unable to login as perms on bash are gone.
15
16 I also notice that courier-imap refuses to run in the right context and
17 always runs as system_u:system_r:initrc_t.
18
19 I previously installed a virtual machine with selinux etc to see if I
20 could get my head round it and it all worked fine.
21
22 What could be the reason for me getting locked out of my system when
23 enforce mode is enabled?
24
25 BTW I have relabeled filesystems several times as it looked originally
26 like things just weren't labeled, however they seem fine until enforce
27 mode is enabled.
28
29 Grateful for any help.
30
31 Thanks
32
33 Matt

Replies

Subject Author
Re: [gentoo-hardened] locked out of selinux Matt Harrison <iwasinnamuknow@×××××××××.com>
Re: [gentoo-hardened] locked out of selinux Matt Harrison <iwasinnamuknow@×××××××××.com>