Why SSH port forwarding fails when system is configured for RSA SecurID?
Issue
-
Trying to connect to SSH forwarded ports (either using DynamicForward or LocalForward techniques) fails with SELinux complaining with the following message in
/var/log/audit/audit.logof the SSH servertype=AVC msg=audit(...): avc: denied { name_connect } for pid=... comm="sshd" dest=XXX scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:ssh_port_t:s0 tclass=tcp_socket - System has been configured by following the document available on the RSA company website RSA Authentication Agent for PAM
Environment
- Red Hat Enterprise Linux (RHEL) 7
- RSA Authentication Agent for PAM
- SELinux
- sshd
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
