Gentoo Archives: gentoo-hardened

From: Julien Thomas <julien.thomas@×××××××××××××.fr>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Can't login by ssh
Date: Thu, 08 Nov 2007 10:10:06
Message-Id: 4732E01F.1000407@enst-bretagne.fr
In Reply to: [gentoo-hardened] Can't login by ssh by Shaochun Wang
1 Hello.
2
3 According to your dmesg message,
4 I think that the password checking binary should be of type
5 system_u:object_r:chkpwd_exec_t, which is not present here.
6
7 However, I do not remember very well if it has to be here or not, as
8 sometimes log messages do not really relfect the object type (in my
9 case), with for instance, labels compressions (type_exec_t -> type_t).
10
11 So, have you check
12 http://www.gentoo.org/proj/en/hardened/selinux/selinux-handbook.xml?part=4&chap=3
13 to see if it's an error produced by an incorrect labelling ?
14
15 for ino=427414, what is the associated file ?
16 See the second possible error, "Incorrect Password File Contexts", of
17 the previous link.
18
19
20
21 Shaochun Wang wrote:
22 > Currently, I use the targeted policy. But I can't login using ssh.
23 > Command dmesg shows the following message:
24 >
25 > audit(1194494942.948:137): avc: denied { entrypoint } for pid=29208
26 > comm="sshd" name="bash" dev=hda5 ino=427414
27 > scontext=user_u:system_r:system_chkpwd_t
28 > tcontext=system_u:object_r:shell_exec_t tclass=file
29 >
30 > Any help?
31 >
32 >

Attachments

File name MIME type
julien_thomas.vcf text/x-vcard
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] Can't login by ssh Shaochun Wang <scwang@××××××.cn>