I tried that command and it came out with an error -<br> &gt;[root@host ~]# chcon -t textrel_shlib_t /opt/cisco-vpnclient/lib/libvpnapi.so<br> &gt; chcon: failed to change context of &gt;/opt/cisco-vpnclient/lib/libvpnapi.so to root:object_r:textrel_shlib_t: Invalid argument<br> and later agian on Pauls adivice I aso ran the command<br> # setsebool -P allow_execmod 1<br> which did not work either.<br> <br> Thanks<br> shyam<br><br><b><i>Daniel J Walsh &lt;dwalsh@redhat.com&gt;</i></b> wrote:<blockquote class="replbq" style="border-left: 2px solid rgb(16, 16, 255); margin-left: 5px; padding-left: 5px;"> yukku yukkoooooo wrote:<br>&gt; Hi,<br>&gt;     I am running on FC4 and I installed Cisco VPN client software, <br>&gt; however when I run vpnclient I am getting the error message :<br>&gt; "vpnclient: error while loading shared libraries: /opt/cisco-vpnclient/lib/libvpnapi.so: cannot restore segment prot after reloc: Permission denied"<br>This is strange.<br><br>Have you
 tried<br><br>chcon -t textrel_shlib_t /opt/cisco-vpnclient/lib/libvpnapi.so<br>&gt; Friendly neighbourhood Paul Howarth correctly guessed it to be related <br>&gt; to SELinux.<br>&gt; I am able to run the vpnclient by disabling the SELinux using<br>&gt; setenforce 0<br>&gt; The chcon command did not work (apparently it is not supposed to work <br>&gt; in FC4)<br>&gt; I get a error message "type=AVC msg=audit(1147460693.437:11955217): <br>&gt; avc: denied { execmod } "<br>&gt; if I disable selinux and run the vpnclient command.<br>&gt; &gt; Paul Howarth wrote :<br>&gt; &gt; &gt; The memory checks are present in FC4 but disabled by default. It <br>&gt; &gt; &gt; appears<br>&gt; &gt; &gt; that they have somehow been enabled on your system.<br>&gt;  This should fix <br>&gt; it:<br>&gt; &gt; &gt; # setsebool -P allow_execmod 1<br>&gt; &gt; <br>&gt; &gt; I gave this command and it still does not work with<br>&gt; &gt; SELinux. So digged a littlebit and gave the command<br>&gt;
 &gt; # getsebool -a | less<br>&gt; &gt; and I got a long output of which I took the ones that might<br>&gt; &gt; make sense to you -<br>&gt; &gt; allow_execmem --&gt; active<br>&gt; &gt; allow_execmod --&gt; active<br>&gt; &gt; allow_execstack --&gt; active<br>&gt; &gt; allow_kerberos --&gt; active<br>&gt; &gt; allow_write_xshm --&gt; active<br>&gt; &gt; allow_ypbind --&gt; active<br>&gt; &gt;&gt; There's something very weird going on there. allow_execmod should do<br>&gt; &gt;&gt; what it says. I'd try asking about this on fedora-selinux-list,<br>&gt;<br>&gt; setsebool with execmod is not working either.<br>&gt; I have attached the relevant files as well. Any ideas ?<br>&gt; This should give you an idea of the SELinux version<br>&gt; &gt; selinux-doc-1.19.5-1.noarch.rpm<br>&gt; &gt;<br>&gt;  selinux-policy-strict-1.23.16-6.noarch.rpm<br>&gt; &gt; selinux-policy-targeted-1.23.16-6.noarch.rpm<br>&gt;<br>&gt; Thanks<br>&gt; Newbie Yukku<br>&gt;<br>&gt;   <br>&gt;<br>&gt;
 ------------------------------------------------------------------------<br>&gt; New Yahoo! Messenger with Voice. Call regular phones from your PC <br>&gt; <http: //us.rd.yahoo.com/mail_us/taglines/postman5/*http://us.rd.yahoo.com/evt="39666/*http://messenger.yahoo.com"> <br>&gt; and save big.<br>&gt; ------------------------------------------------------------------------<br>&gt;<br>&gt; type=SYSCALL msg=audit(1147715609.949:3621791): arch=40000003 syscall=4 success=yes exit=1 a0=3 a1=bfc7b7b8 a2=1 a3=bfc7b7b8 items=0 pid=4330 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 comm="setenforce" exe="/usr/sbin/setenforce"<br>&gt; type=AVC msg=audit(1147715609.949:3621791): avc: granted { setenforce } for pid=4330 comm="setenforce" scontext=root:system_r:unconfined_t tcontext=system_u:object_r:security_t tclass=security<br>&gt; type=AVC_PATH msg=audit(1147715612.195:3634219):  path="/opt/cisco-vpnclient/lib/libvpnapi.so"<br>&gt; type=SYSCALL
 msg=audit(1147715612.195:3634219): arch=40000003 syscall=125 per=400000 success=yes exit=0 a0=9be000 a1=41000 a2=5 a3=bfd74540 items=0 pid=4332 auid=4294967295 uid=500 gid=500 euid=500 suid=500 fsuid=500 egid=500 sgid=500 fsgid=500 comm="vpnclient" exe="/opt/cisco-vpnclient/bin/vpnclient"<br>&gt; type=AVC msg=audit(1147715612.195:3634219): avc: denied { execmod } for pid=4332 comm="vpnclient" name=libvpnapi.so dev=hda3 ino=32474 scontext=user_u:system_r:unconfined_t tcontext=root:object_r:usr_t tclass=file<br>&gt;   <br>&gt; ------------------------------------------------------------------------<br>&gt;<br>&gt; SELinux status:                 enabled<br>&gt; SELinuxfs mount:                /selinux<br>&gt; Current mode:                   enforcing<br>&gt; Mode from config file:          enforcing<br>&gt; Policy version:                 19<br>&gt; Policy from config file:        targeted<br>&gt;<br>&gt; Policy booleans:<br>&gt; NetworkManager_disable_trans   
 inactive<br>&gt; allow_execmem                   active<br>&gt; allow_execmod                   active<br>&gt; allow_execstack                 active<br>&gt; allow_kerberos                  active<br>&gt; allow_write_xshm                inactive<br>&gt; allow_ypbind                    inactive<br>&gt; apmd_disable_trans              inactive<br>&gt; arpwatch_disable_trans          inactive<br>&gt; auditd_disable_trans            inactive<br>&gt; bluetooth_disable_trans         inactive<br>&gt; canna_disable_trans             inactive<br>&gt; cardmgr_disable_trans           inactive<br>&gt; comsat_disable_trans            inactive<br>&gt; cupsd_config_disable_trans      inactive<br>&gt; cupsd_disable_trans             inactive<br>&gt; cvs_disable_trans               inactive<br>&gt; cyrus_disable_trans             inactive<br>&gt; dbskkd_disable_trans            inactive<br>&gt; dhcpc_disable_trans             inactive<br>&gt; dhcpd_disable_trans            
 inactive<br>&gt; dovecot_disable_trans           inactive<br>&gt; fingerd_disable_trans           inactive<br>&gt; ftp_home_dir                    active<br>&gt; ftpd_disable_trans              inactive<br>&gt; ftpd_is_daemon                  active<br>&gt; hald_disable_trans              inactive<br>&gt; hotplug_disable_trans           inactive<br>&gt; howl_disable_trans              inactive<br>&gt; httpd_builtin_scripting         active<br>&gt; httpd_can_network_connect       inactive<br>&gt; httpd_disable_trans             inactive<br>&gt; httpd_enable_cgi                active<br>&gt; httpd_enable_homedirs           active<br>&gt; httpd_ssi_exec                  active<br>&gt; httpd_suexec_disable_trans      inactive<br>&gt; httpd_tty_comm                  inactive<br>&gt; httpd_unified                   active<br>&gt; i18n_input_disable_trans        inactive<br>&gt; inetd_child_disable_trans       inactive<br>&gt; inetd_disable_trans             inactive<br>&gt;
 innd_disable_trans              inactive<br>&gt; kadmind_disable_trans           inactive<br>&gt; klogd_disable_trans             inactive<br>&gt; krb5kdc_disable_trans           inactive<br>&gt; ktalkd_disable_trans            inactive<br>&gt; lpd_disable_trans               inactive<br>&gt; mysqld_disable_trans            inactive<br>&gt; named_disable_trans             inactive<br>&gt; named_write_master_zones        inactive<br>&gt; nfs_export_all_ro               active<br>&gt; nfs_export_all_rw               active<br>&gt; nmbd_disable_trans              inactive<br>&gt; nscd_disable_trans              inactive<br>&gt; ntpd_disable_trans              inactive<br>&gt; portmap_disable_trans           inactive<br>&gt; postgresql_disable_trans        inactive<br>&gt; pppd_disable_trans              inactive<br>&gt; pppd_for_user                   inactive<br>&gt; privoxy_disable_trans           inactive<br>&gt; ptal_disable_trans              inactive<br>&gt;
 radiusd_disable_trans           inactive<br>&gt; radvd_disable_trans             inactive<br>&gt; read_default_t                  active<br>&gt; rlogind_disable_trans           inactive<br>&gt; rsync_disable_trans             inactive<br>&gt; samba_enable_home_dirs          inactive<br>&gt; saslauthd_disable_trans         inactive<br>&gt; slapd_disable_trans             inactive<br>&gt; smbd_disable_trans              inactive<br>&gt; snmpd_disable_trans             inactive<br>&gt; squid_connect_any               inactive<br>&gt; squid_disable_trans             inactive<br>&gt; stunnel_disable_trans           inactive<br>&gt; stunnel_is_daemon               inactive<br>&gt; syslogd_disable_trans           inactive<br>&gt; system_dbusd_disable_trans      inactive<br>&gt; telnetd_disable_trans           inactive<br>&gt; tftpd_disable_trans             inactive<br>&gt; udev_disable_trans              inactive<br>&gt; use_nfs_home_dirs               inactive<br>&gt;
 use_samba_home_dirs             inactive<br>&gt; uucpd_disable_trans             inactive<br>&gt; winbind_disable_trans           inactive<br>&gt; ypbind_disable_trans            inactive<br>&gt; ypserv_disable_trans            inactive<br>&gt; zebra_disable_trans             inactive<br>&gt;   <br>&gt; ------------------------------------------------------------------------<br>&gt;<br>&gt; --<br>&gt; fedora-selinux-list mailing list<br>&gt; fedora-selinux-list@redhat.com<br>&gt; https://www.redhat.com/mailman/listinfo/fedora-selinux-list<br><br></http:></blockquote><br><p>
                <hr size=1>Love cheap thrills? Enjoy PC-to-Phone <a href="http://us.rd.yahoo.com/mail_us/taglines/postman9/*http://us.rd.yahoo.com/evt=39666/*http://messenger.yahoo.com/"> calls to 30+ countries</a> for just 2¢/min with Yahoo! Messenger with Voice.