The samba net command does not execute unless I change selinux to
permissive.
Apr 10 19:12:02 localhost kernel: audit(1144710722.223:158): avc: denied
{ write } for pid=3615 comm="net" name="group_mapping.tdb" dev=dm-0
ino=3310700 scontext=root:system_r:samba_net_t:s0-s0:c0.c255
tcontext=root:object_r:samba_var_t:s0 tclass=file
Apr 10 19:12:02 localhost net: [2006/04/10 19:12:02.227587, 0]
groupdb/mapping.c:init_group_mapping(134)
Apr 10 19:12:02 localhost net: Failed to open group mapping database
Apr 10 19:12:02 localhost net: [2006/04/10 19:12:02.228030, 0]
groupdb/mapping.c:enum_group_mapping(415)
Apr 10 19:12:02 localhost net: failed to initialize group mapping
Is there a simple fix while leaving selinux enabled?
Mark Orenstein
East Granby School System
--
fedora-selinux-list mailing list
fedora-selinux-list(a)redhat.com
https://www.redhat.com/mailman/listinfo/fedora-selinux-list
Just to be more specific, it is the "net groupmap" command that will not
execute properly with selinux enabled.