Why SELinux report errors on syslogd ?
Issue
- The system got many SELinux errors in /var/log/messages.
kernel: audit(1269720122.791:1406): avc: denied { read } for pid=3218 comm="syslogd" name="mail" dev=sda6 ino=12 scontext=user_u:system_r:syslogd_t tcontext=system_u:object_r:mail_spool_t tclass=lnk_file
kernel: audit(1269720122.791:1407): avc: denied { search } for pid=3218 comm="syslogd" name="spool" dev=sda6 ino=48097 scontext=user_u:system_r:syslogd_t tcontext=system_u:object_r:var_spool_t tclass=dir
Environment
- Red Hat Enterprise Linux 4
- Red Hat Enterprise Linux 5
- SELinux
- rsyslogd
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.