1 |
Hello. |
2 |
|
3 |
According to your dmesg message, |
4 |
I think that the password checking binary should be of type |
5 |
system_u:object_r:chkpwd_exec_t, which is not present here. |
6 |
|
7 |
However, I do not remember very well if it has to be here or not, as |
8 |
sometimes log messages do not really relfect the object type (in my |
9 |
case), with for instance, labels compressions (type_exec_t -> type_t). |
10 |
|
11 |
So, have you check |
12 |
http://www.gentoo.org/proj/en/hardened/selinux/selinux-handbook.xml?part=4&chap=3 |
13 |
to see if it's an error produced by an incorrect labelling ? |
14 |
|
15 |
for ino=427414, what is the associated file ? |
16 |
See the second possible error, "Incorrect Password File Contexts", of |
17 |
the previous link. |
18 |
|
19 |
|
20 |
|
21 |
Shaochun Wang wrote: |
22 |
> Currently, I use the targeted policy. But I can't login using ssh. |
23 |
> Command dmesg shows the following message: |
24 |
> |
25 |
> audit(1194494942.948:137): avc: denied { entrypoint } for pid=29208 |
26 |
> comm="sshd" name="bash" dev=hda5 ino=427414 |
27 |
> scontext=user_u:system_r:system_chkpwd_t |
28 |
> tcontext=system_u:object_r:shell_exec_t tclass=file |
29 |
> |
30 |
> Any help? |
31 |
> |
32 |
> |