Why SSH port forwarding fails when system is configured for RSA SecurID?

Solution Verified - Updated -

Issue

  • Trying to connect to SSH forwarded ports (either using DynamicForward or LocalForward techniques) fails with SELinux complaining with the following message in /var/log/audit/audit.log of the SSH server

    type=AVC msg=audit(...): avc:  denied  { name_connect } for  pid=... comm="sshd" dest=XXX scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:ssh_port_t:s0 tclass=tcp_socket
    
  • System has been configured by following the document available on the RSA company website RSA Authentication Agent for PAM

Environment

  • Red Hat Enterprise Linux (RHEL) 7
  • RSA Authentication Agent for PAM
  • SELinux
  • sshd

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content