Re: FC5, Apache, Bugzilla, SELinux issues

Argh! did you spot my deliberate mistake there! /slaps forehead.

Ignore me.

*hangs head*

On 04/01/07, R Edmonds < redmonds98 googlemail com> wrote:
I seem to have fallen at the first hurdle.  Following your instructions in the thread:

Enable CGI scripts:
# setsebool -P httpd_enable_cgi 1

I get the following:

[root svn ~]# setsebool -P httpd_enable_sgi 1
libsemanage.dbase_llist_set: record not found in the database
libsemanage.dbase_llist_set: could not set record value
Could not change boolean httpd_enable_sgi
Could not change policy booleans
[root svn ~]#

Perhaps I've made a schoolboy error here?  Some prerequisite action to make setsebool happy?

Best regards,


On 04/01/07, R Edmonds <redmonds98 googlemail com> wrote:
Hi Paul,

Thanks for your fast reply.  I'll give this a blast right now.

Best regards,


On 04/01/07, Paul Howarth < paul city-fan org> wrote:

R Edmonds wrote:
> Greetings out there in Penguin-land!
> I'm going through the rather painful process of installing Bugzilla on an
> SELinux FC5 box. I'm almost there now, I think, however I'm trying to add a
> local policy to SELinux for allowing Apache to execute .cgi scripts, and
> have hit a brick wall.

Could you please take a look at
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188359#c45 where an
initial SELinux policy for the bugzilla package in Fedora Extras was
proposed. Please try using this, following the instructions at the URL
mentioned instead of using the module you generated using audit2allow
(make sure you have the latest selinux-policy-devel package installed).

It was hoped to get this included much earlier but there was no active
user of bugzilla that wanted to use SELinux around at that time to do
any testing. Getting this working for you could benefit lots of people
in the future.

Cheers, Paul.

