selinux is blocking keepalived scripts
Issue
- Scripts from
/usr/libexec/keepalivedcalled bykeepalivedare getting blocked. - The
keepalivedservice lacksSELinuxprivleges toexecscripts, including tracking scripts and notification scripts. - Getting below
AVCin/var/log/messages:
type=1400 audit(1442276258.336:33667): avc: denied { search } for pid=23327 comm="killall" name="1034" dev=proc ino=10849 scontext=unconfined_u:system_r:keepalived_t:s0 tcontext=system_u:system_r:crond_t:s0-s0:c0.c1023 tclass=dir
Environment
- Red Hat Enterprise Linux 6.6
- SELinux-policy
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.