Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 19/20 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 20th December 2006, 04:59 PM
edcrown1 Offline
Registered User
 
Join Date: Jun 2006
Posts: 2
su error message

Hi,
Running FC5 on a couple of servers. All was fine until the recent SSH2 upgrade. Since the upgrade, my users can no longer run su. I can log-in as root via SSH, but cannot execute su as a normal user.

The error in the message log is
kernel: audit(1166633353.814:277): avc: denied { execute } for pid=17320 comm="su" name="xauth" dev=dm-0 ino=13359914 scontext=system_u:system_r:initrc_su_t:s0 tcontext=system_u:object_r:xauth_exec_t:s0 tclass=file

This only occurs on FC5. Am I missing something obvious?

Greatly appreciate your help.

thanks,
Ed
Reply With Quote
  #2  
Old 20th December 2006, 11:50 PM
stoggy Offline
Registered User
 
Join Date: Dec 2006
Location: freedonia
Posts: 128
Thats a selinux permission violation. Selinux is keeping them from running the command su. This is probably a mess up on the fedora core maintainers part.

To check this you can go into the selinux setup (there is a gui app for this) disable selinux protection and try to run su if it works then you know selinux is causing the problem. The gui app is under System > Administration > Security Level and Firewall ... Then click on the selinux tab and set SElinux Setting to Disabled. If selinux is the problem, this happens a lot in fc ... try checking for new updates. Sometimes the fedora core maintainers release a fix to a package but dont update their policies until later so selinux breaks stuff until the new policies get installed.
Reply With Quote
  #3  
Old 21st December 2006, 05:13 PM
edcrown1 Offline
Registered User
 
Join Date: Jun 2006
Posts: 2
Thanks for the info. You were correct on selinux being the issue. will look for the latest updates and read on creating new policies.

ed
Reply With Quote
Reply

Tags
error, message

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
trying to install NCTUNS - ERROR MESSAGE " ERROR: Cannot find gcc or g++ compiler" rodmarino Using Fedora 3 1st October 2007 07:13 PM
what is this error message? abubin Hardware & Laptops 3 28th March 2007 04:56 AM
error message gooch Installation, Upgrades and Live Media 2 4th October 2005 07:33 AM
kernel error message: hda: dma_intr: error=0x84... HadroLepton Using Fedora 5 13th January 2005 05:38 PM
Error message LLS Servers & Networking 1 29th December 2004 06:41 PM


Current GMT-time: 08:07 (Friday, 25-04-2014)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat