Gentoo Archives: gentoo-hardened

From: Dale Pontius <DEPontius@××××××.net>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] SELinux n00b questions
Date: Mon, 14 Nov 2005 22:40:33
Message-Id: 4379118D.9080005@edgehp.net
In Reply to: Re: [gentoo-hardened] SELinux n00b questions by Peter Shaw
1 Peter Shaw wrote:
2
3 >On Monday 14 November 2005 02:51, Dale Pontius wrote:
4 >
5 >
6 >>I decided to try running BIND on the SELinux system. I get this message:
7 >> * Starting named ...
8 >>named: capset failed: Operation not permitted: please ensure that the
9 >>capset kernel module is loaded. see insmod(8)
10 >>
11 >>I've made sure that "commoncap" was built and loaded prior to trying to
12 >>start BIND. A bit
13 >>of google searching, and this seemed to have helped everyone else, but
14 >>not me.
15 >>
16 >>
17 >I had the same problem and googled it, and the module I found I had to put
18 >into /etc/modules.autoload.d/kernel-2.6 was ¨capability¨, not ¨commoncap¨.
19 >But perhaps you´re using a 2.4 kernel and it´s different - i just subscribed
20 >to the mailing list and didn´t see the original post.
21 >
22 >
23 I saw the "capability" stuff too, and thought that was the same as
24 "commoncap". So
25 now I have to ask... Where do you turn on "capability"? I did a "grep
26 CAP .config"
27 and got only 2 entries, the one that produced commoncap, and another
28 that was
29 completely unrelated. (sound, maybe?) I'm running 2.6, by the way.
30
31 Dale
32 --
33 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] SELinux n00b questions Antoine Martin <antoine@××××××××××.uk>
Re: [gentoo-hardened] SELinux n00b questions Dale Pontius <DEPontius@××××××.net>