Gentoo Archives: gentoo-hardened

From: petre rodan <kaiowas@g.o>
To: Richard Simpson <richard.simpson@×××××.com>
Cc: gentoo-hardened <gentoo-hardened@l.g.o>
Subject: Re: [gentoo-hardened] [selinux] empty ntpd.pid
Date: Thu, 28 Oct 2004 14:48:02
Message-Id: 418106F9.1050003@gentoo.org
In Reply to: [gentoo-hardened] [selinux] empty ntpd.pid by Richard Simpson
1 Hi!
2
3 Richard Simpson wrote:
4 > Greetings:
5 >
6 > I'm trying to install ntpd on an selinux-enabled gentoo system, and one of
7 > the stranger problems I'm having is with /var/run/ntpd.pid. The file is
8 > being created with a context of initrc_var_run_t, but the pid is never
9 > written to the file. I get an avc denial and a log entry from ntpd about not
10 > being able to access the pid file. The ntpd.te policy expects this file to
11 > have a context of ntpd_var_run_t. I see that the /etc/init.d/ntpd script
12 > creates the empty ntpd.pid because it wants to `chown ntp:ntp` before it
13 > starts the daemon, ergo the initrc_var_run_t context. Is this a correct
14 > behavior? Solutions?
15
16 please open a bug about this in bugs.gentoo.org and assign it to me.
17
18 thanks,
19 peter
20
21 --
22 petre rodan
23 <kaiowas@g.o>
24 Developer,
25 Hardened Gentoo Linux

Attachments

File name MIME type
signature.asc application/pgp-signature