免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 1193 | 回复: 0
打印 上一主题 下一主题

如何修改一个文件的SELinux security categories ? [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2008-10-25 22:37 |只看该作者 |倒序浏览
按照Redhat的文档,用chcat -- +Marketing filename 把filename文件添加到Marketing这个categories。但是无论使用在Marketing这个categories的hesidu用户还是root都不能添加。提示:
chcon: failed to change context of financerecords.txt to user_u:object_r:user_home_t:s0:c0: 权限不够
Summary
SELinux is preventing /usr/bin/chcon (unconfined_t) "relabelto" to financerecord.txt (bin_t).
Detailed Description
SELinux denied access requested by /usr/bin/chcon. It is not expected that this access is required by /usr/bin/chcon and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access.
Allowing Access
Sometimes labeling problems can cause SELinux denials. You could try to restore the default system file context for financerecord.txt, restorecon -v financerecord.txt If this does not work, there is currently no automatic way to allow this access. Instead, you can generate a local policy module to allow this access - see FAQ Or you can disable SELinux protection altogether. Disabling SELinux protection is not recommended. Please file a bug report against this package.
Additional Information
Source Context:  user_u:system_r:unconfined_t
Target Context:  user_u:object_r:bin_t:Marketing
Target Objects:  financerecord.txt [ file ]
Affected RPM Packages:  coreutils-5.97-12.1.el5 [application]
Policy RPM:  selinux-policy-2.4.6-30.el5
Selinux Enabled:  True
Policy Type:  targeted
MLS Enabled:  True
Enforcing Mode:  Enforcing
Plugin Name:  plugins.catchall_fileHost Name:  localhost.localdomain
Platform:  Linux localhost.localdomain 2.6.18-8.el5 #1 SMP Fri Jan 26 14:15:21 EST 2007 i686 i686
Alert Count:  3
Line Numbers:   
Raw Audit Messages :avc: denied { relabelto } for comm="chcon" dev=dm-0 egid=0 euid=0 exe="/usr/bin/chcon" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="financerecord.txt" pid=23994 scontext=user_u:system_r:unconfined_t:s0 sgid=0 subj=user_u:system_r:unconfined_t:s0 suid=0 tclass=file tcontext=user_u:object_r:bin_t:s0:c0 tty=pts0 uid=0
               
               
               

本文来自ChinaUnix博客,如果查看原文请点:http://blog.chinaunix.net/u/6949/showart_1335354.html
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP