Selinux update breaks nscd?

Tim Fenn fenn at stanford.edu
Mon Jun 13 20:46:05 UTC 2005


On Mon, Jun 13, 2005 at 01:11:48PM -0700, Richard Crawford wrote:
> On Monday 13 June 2005 13:06, Jason L Tibbitts III wrote:
> > Is anyone else noticing that nscd is rather broken after the resent
> > selinux-policy-targeted-1.17.30-3.2?  For me, nscd -K, -i and -g (as
> > root) are broken because they can't access the control socket, and
> > nscd can't talk to the LDAP server to discover users because it can't
> > read /usr/share/ssl/cacert.pem.
> 

not sure about this one... what are the avc errors you get?  The
fellows at fedora-selinux are usually very helpful with this kind of
stuff...

> I noticed that it broke quite a few things for me.  I couldn't launch 
> OpenOffice.org, and the installation of Gallery (the PHP web application) 
> that I have running on my FC3 webserver would no longer work, even after I 
> changed the security context for the program files.
> 

I also had some recent problems with php scripts in httpd being denied
writes upon upgrading my booleans file.  Here's what fixed it for me:

https://www.redhat.com/archives/fedora-selinux-list/2005-June/msg00065.html

setsebool -P httpd_builtin_scripting=1

Hope it helps,
Tim Fenn

-- 
Morals?  I eat communism and $h!t America, brother.  --Seanbaby




More information about the fedora-list mailing list