Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.
Bug 224437 - AVC denials prevent remote SSH logins
Summary: AVC denials prevent remote SSH logins
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted
Version: rawhide
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Ben Levenson
Depends On:
TreeView+ depends on / blocked
Reported: 2007-01-25 18:10 UTC by Daniel Berrange
Modified: 2007-11-30 22:11 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2007-08-01 18:52:15 UTC

Attachments (Terms of Use)

Description Daniel Berrange 2007-01-25 18:10:27 UTC
Description of problem:
 ssh root@[removed hostname]
/bin/bash: Permission denied
Connection to [removed hostname] closed.

Looking in the /var/log/audit/audit.log file after this failure I see:

type=AVC msg=audit(1169748817.951:110): avc:  denied  { entrypoint } for 
pid=2671 comm="sshd" name="bash" dev=dm-0 ino=17305623
tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC_PATH msg=audit(1169748817.951:110):  path="/bin/bash"

I am logging in using SSH agent, but logging in with passwords fails too.

Version-Release number of selected component (if applicable):

The rest of the machine is updated to rawhide as of 11 EST  Jan 25

How reproducible:
All remote ssh logins

Steps to Reproduce:
1. Boot host with SELinux enabled & sshd running
2. Attempt to login in remotely with SSH
Actual results:
The connection is dropped

Expected results:
Login completes

Additional info:
I have checked the SSH daemon is running in the sshd_t domain:

system_u:system_r:sshd_t:SystemLow-SystemHigh root 2028 0.0  0.0 44296 1096 ? 
Ss   13:12   0:00 /usr/sbin/sshd

And have rebooted & done a full filesystem re-label several times over.

Comment 1 Daniel Walsh 2007-01-25 19:21:54 UTC
Fixed in selinux-policy-2.5.2-1.fc7

Comment 2 Daniel Berrange 2007-08-01 18:52:15 UTC
Was fixed a while ago...

Note You need to log in before you can comment on or make changes to this bug.