Starting stunnel from xinetd

Ian Pilcher arequipeno at gmail.com
Mon Mar 10 11:54:56 UTC 2008


Running fully updated Fedora 8, trying to start stunnel from xinetd, and
getting a couple of denials:

type=AVC msg=audit(1205149512.996:2338): avc:  denied  { write } for
pid=14322 comm="stunnel" name="random_seed" dev=md1 ino=819429
scontext=unconfined_u:system_r:stunnel_t:s0-s0:c0.c1023
tcontext=unconfined_u:object_r:stunnel_etc_t:s0 tclass=file

type=AVC msg=audit(1205149512.998:2339): avc:  denied  { name_bind } for
 pid=14322 comm="stunnel" src=2873
scontext=unconfined_u:system_r:stunnel_t:s0-s0:c0.c1023
tcontext=system_u:object_r:port_t:s0 tclass=tcp_socket

Aren't these things that stunnel should be expected to do?

-- 
========================================================================
Ian Pilcher                                         arequipeno at gmail.com
========================================================================




More information about the fedora-selinux-list mailing list