You are not logged in.
Pages: 1
I've setup SELinux as per the wiki (minus editing a python script to fix a syntax error and a PKGBUILD to prevent it recloning the bad repo with the bad script)
However when I `setenforce 1` I get kicked off my SSH connection. Any attempts to reconnect immediately disconnect on connection
Unfortunately I don't have physical access (cloud hosted server) so I have to reboot to get back in. However I can verify a web application running on the server still runs so it doesn't go down completely when I can't login
Is there a way to get SSH connection working with SElinux? SElinux seems to be by far the best security solution, especially for a remotely administered server
Offline
leave it in permissive mode, look at the logs and plugging it into something like audit2allow. Only set it to enforcing once you're not getting denials from ssh related things (and other potentially important things)
Offline
Are you still using Zen or Arch Linux now?
In the latter case, please provider your /var/log/audit/audit.log.
Inofficial first vice president of the Rust Evangelism Strike Force
Offline
I hope you have a hearty machine, it's long. /var/log/audit is empty, I got the log via 'journalctl|grep denied > audit.log'
Btw this is a completely different server - that was my PC (which used the zen **installer** for arch Linux, primarily because the network I regularly use requires browser sign-in)
Offline
1) The file cannot be found on the server.
2) Please do not pre-filter the output.
Inofficial first vice president of the Rust Evangelism Strike Force
Offline
1) The file cannot be found on the server.
2) Please do not pre-filter the output.
So....you'd rather me posted the entire output of journalctl?
Offline
I would suggest limiting journalctl output to one affected boot.
Offline
@g2g591 no go
Audit2allow returns
Traceback (most recent call last): File "/usr/bin/audit2allow", line 25, in <module> import sepolgen.audit as audit File "/usr/lib/python3.8/site-packages/sepolgen/audit.py", line 24, in <module> from . import access File "/usr/lib/python3.8/site-packages/sepolgen/access.py", line 37, in <module> from selinux import audit2why ImportError: cannot import name 'audit2why' from 'selinux'
Offline
@g2g591 no go
Audit2allow returnsTraceback (most recent call last): File "/usr/bin/audit2allow", line 25, in <module> import sepolgen.audit as audit File "/usr/lib/python3.8/site-packages/sepolgen/audit.py", line 24, in <module> from . import access File "/usr/lib/python3.8/site-packages/sepolgen/access.py", line 37, in <module> from selinux import audit2why ImportError: cannot import name 'audit2why' from 'selinux'
Install selinux-python (AUR) . Believe that should contain the needed bits.
Last edited by g2g591 (2019-11-21 11:38:42)
Offline
alexia-v2 wrote:@g2g591 no go
Audit2allow returnsTraceback (most recent call last): File "/usr/bin/audit2allow", line 25, in <module> import sepolgen.audit as audit File "/usr/lib/python3.8/site-packages/sepolgen/audit.py", line 24, in <module> from . import access File "/usr/lib/python3.8/site-packages/sepolgen/access.py", line 37, in <module> from selinux import audit2why ImportError: cannot import name 'audit2why' from 'selinux'
Install selinux-python (AUR) . Believe that should contain the needed bits.
Still no go, was already installed
Offline
g2g591 wrote:alexia-v2 wrote:@g2g591 no go
Audit2allow returnsTraceback (most recent call last): File "/usr/bin/audit2allow", line 25, in <module> import sepolgen.audit as audit File "/usr/lib/python3.8/site-packages/sepolgen/audit.py", line 24, in <module> from . import access File "/usr/lib/python3.8/site-packages/sepolgen/access.py", line 37, in <module> from selinux import audit2why ImportError: cannot import name 'audit2why' from 'selinux'
Install selinux-python (AUR) . Believe that should contain the needed bits.
Still no go, was already installed
Well, some selinux related python bit seems to be missing... If your heart is set on selinux, it may be better to try out a distro where it's officially supported rather than the barebones reference policy which apparently isn't properly set to allow ssh.
Anyway, back to Arch, ensure policycoreutils is installed (thats the package audit2allow comes in on other distributions) and look at its optional dependencies and see if installing one of them makes it work.
Offline
alexia-v2 wrote:g2g591 wrote:Install selinux-python (AUR) . Believe that should contain the needed bits.
Still no go, was already installed
Well, some selinux related python bit seems to be missing... If your heart is set on selinux, it may be better to try out a distro where it's officially supported rather than the barebones reference policy which apparently isn't properly set to allow ssh.
Anyway, back to Arch, ensure policycoreutils is installed (thats the package audit2allow comes in on other distributions) and look at its optional dependencies and see if installing one of them makes it work.
In a couple of days I'm going to set up a vm with arch to try screwing with sepolicy but for now switched to a different distro on my production servers. Will get back to you once I get it set up
Offline
Pages: 1