ラベル SElinux の投稿を表示しています。 すべての投稿を表示
ラベル SElinux の投稿を表示しています。 すべての投稿を表示

2018-11-02

pip install --userでインストールしたパッケージをprocmailで使用する

ホームディレクトリにPIPをつかってパッケージをインストールすると、.local/lib/の下に展開される。 ところが、このディレクトリはSELinuxのコンテクストがunconfined_u:object_r:gconf_home_t:s0になっており、問題が生じる。

例えば、ProcmailからPythonを呼び出し、その中でモジュールをインポートしようとすると、以下のようなエラーメッセージが出る。 以下はBeautifulSoupを使用した例。

Traceback (most recent call last):
  File "/tmp/a.py", line 3, in 
    from bs4 import BeautifulSoup
ImportError: cannot import name 'BeautifulSoup'

とりあえず以下のコマンドで問題を回避する。 $ chcon -R unconfined_u:object_r:user_home_t:s0 .local/lib/python3.4/site-packages/

2018-10-21

EL7にてユーザーのpublic_htmlを公開する手順

Scientific Linux 7 (CentOS 7と同様にRedhat Enterprise Linux 7のクローン, 以下EL7) において, ユーザーのpublic_html下にあるコンテンツをApacheで公開するときの手順をまとめる.

Apacheのインストール

$ sudo yum install httpd

Apache上の設定

$ sudoedit /etc/httpd/conf.d/userdir.conf
以下のように disable の部分をコメントアウトし, 代わりに public_html の箇所を有効にする.
<IfModule mod_userdir.c>
    # UserDir disabled
    UserDir public_html
</IfModule>

SELinuxの設定

$ restorecon -R ~/public_html
$ sudo setsebool -P httpd_enable_homedirs 1
EL7ではデフォルトでhttpd_enable_homedirsが無効に設定されているので, これを有効にする必要がある.

Wirewalldの設定

$ sudo firewall-cmd --add-service=http
これでアクセスできることを確認したのち, 以下のコマンドでパーマネントな設定にする.
$ sudo firewall-cmd --permanent --add-service=http

2018-10-20

新規インストールしたサーバーにSSHの公開鍵認証でログインできない

新しくインストールしたScientific Linux 7 (CentOSと同様にRedhat Enterprise Linuxのクローン) サーバーに公開鍵認証をつかってSSHログインしようとすると, なぜか公開鍵をつかってくれない...

クライアント側のデバッグ情報を ssh -vvv で表示.

  debug1: Offering public key: RSA SHA256:xxxx /home/dir/.ssh/id_rsa
  debug3: send_pubkey_test
  debug3: send packet: type 50
  debug2: we sent a publickey packet, wait for reply
  debug3: receive packet: type 51
  debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic,password
  debug2: we did not send a packet, disable method

サーバー側にデバッグ設定を追加. ファイル

LogLevel DEBUG
サーバー側のログ /var/log/secure
Oct 20 13:37:14 host sshd[xxxx]: debug1: trying public key file /home/xxxx/.ssh/authorized_keys
Oct 20 13:37:14 host sshd[xxxx]: debug1: Could not open authorized keys '/home/xxxx/.ssh/authorized_keys': Permission denied

結局のところ, SELinuxが原因だった. .sshを古いマシンからコピーしたので, 正しくコンテクストが設定されていなかった.

restorecon -R ~/.ssh
これまでは, chmodだけで良かった...
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys

2014-08-16

RHEL7にてNFS上にホームディレクトリをおくときの設定

RHEL7のクローンであるSL7では, ホームディレクトリをNFS上においていると, SSHでログインする際に公開鍵暗号による認証が使用できない. 以下の設定で, 回避する.
$ sudo setsebool -P use_nfs_home_dirs on

2011-01-15

SELinux における共有ライブラリのコンテキスト

共有ライブラリ (*.so) は, プログラムの実行時に ld.so によって自動的にリンクされるオブジェクトです. しかし, SELinux を使用していると,
error while loading shared libraries: *.so:
cannot restore segment prot after reloc: Permission denied
といったエラーが出ることがあります.

例えば, Firefox などのようにバイナリをダウンロードし展開して使用すると, このようなエラーに遭遇することがあるでしょう.

このときには, chcon を使用して, 問題の共有ライブラリのセキュリティコンテキストの種類を textrel_shlib_t に変更しましょう.

chcon -t textrel_shlib_t *.so
もし, 共有ライブラリがたくさんあるのであれば, find を使用して,
find -name '*.so*' | xargs echo chcon -t textrel_shlib_t
とすると, サブディレクトリにある共有ライブラリのセキュリティコンテキストも変えることができます.

2011-01-04

Samba サーバを SELinux 環境で使用する

Fedora 14 で smb サービスを起動し, Windows から Linux 上のホームディレクトリを読み出そうとすると,
smbd/notify_inotify.c:421(inotify_watch) inotify_add_watch returned Permission denied
といったログが出力され, Windows からディレクトリ内のファイル一覧を取得できないことがある.

このとき, SELinux がファイルへのアクセスを妨げている可能性がある.

SELinux のマニュアルはいくつかあるが, samba_selinux(8) に samba を使用する際の操作方法などが例を交えてかかれている.

これにしたがって,

sudo setsebool -P samba_enable_home_dirs 1
と命令すると, Windows からホームディレクトリを読み出せるようになるだろう.

2010-11-18

SSH ポートフォワードの失敗

Fedora 14 で SSH ポートフォワードを使おうとすると,
channel 2: open failed: administratively prohibited: open failed
と出力される. この原因はいろいろ考えられるが, いくつかをあげる.
  • sshd の設定で禁止されている.
  • SE Linux により禁止されている.
まずは /etc/ssh/sshd_config に
AllowTcpForwarding yes
がかかれているかを確認. 私の環境では AllowTcpForwarding がコメントアウトされていたが, デフォルトは yes なので問題ない. /var/log/message をみると,
setroubleshoot: SELinux is preventing /usr/sbin/sshd "name_connect" access on <Unknown>. For complete SELinux messages. run sealert -l 1d8e1b1c-526e-4214-97be-98b8d48b5950
と出力されていた. メッセージのとおり, sealert -l 1d8e1b1c-526e-4214-97be-98b8d48b5950を実行すると,
アクセスを許可:
Confined processes can be configured to run requiring different access, SELinux
provides booleans to allow you to turn on/off access as needed. The boolean
sshd_forward_ports is set incorrectly.
Boolean Description:
allow sshd to forward port connections

Fix コマンド:
# setsebool -P sshd_forward_ports 1
と許可する方法を教えてもらえたので,
$ sudo setsebool -P sshd_forward_ports 1 
とコマンドをいれた. setsebool が終了するまで数秒かかったが, ポートフォワードを使用できるようになった.

追記: X11 forwarding のみ失敗する場合は, xauth がインストールされていないことが原因かもしれない. No xauth Program; Cannot Forward With Spoofing Error and Solution