Why SSH port forwarding fails when system is configured for RSA SecurID?
Issue
-
Trying to connect to SSH forwarded ports (either using DynamicForward or LocalForward techniques) fails with SELinux complaining with the following message in
/var/log/audit/audit.logof the SSH servertype=AVC msg=audit(...): avc: denied { name_connect } for pid=... comm="sshd" dest=XXX scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:ssh_port_t:s0 tclass=tcp_socket - System has been configured by following the document available on the RSA company website RSA Authentication Agent for PAM
Environment
- Red Hat Enterprise Linux (RHEL) 7
- RSA Authentication Agent for PAM
- SELinux
- sshd
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.