Why SSH port forwarding fails when system is configured for RSA SecurID?

Solution Verified - Updated -

Issue

  • Trying to connect to SSH forwarded ports (either using DynamicForward or LocalForward techniques) fails with SELinux complaining with the following message in /var/log/audit/audit.log of the SSH server

    type=AVC msg=audit(...): avc:  denied  { name_connect } for  pid=... comm="sshd" dest=XXX scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:ssh_port_t:s0 tclass=tcp_socket
    
  • System has been configured by following the document available on the RSA company website RSA Authentication Agent for PAM

Environment

  • Red Hat Enterprise Linux (RHEL) 7
  • RSA Authentication Agent for PAM
  • SELinux
  • sshd

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.