Nagios plugin check_mailq fails to run on RHEL 7.8, an AVC is seen
Issue
-
Since upgrading the system to RHEL 7.8, the Nagios plugin
check_mailq
cannot execute anymoreNRPE: Unable to read output
-
The following AVC is seen in
/var/log/audit/audit.log
type=AVC msg=audit(XXX): avc: denied { execute } for pid=XXX comm="check_mailq" path="/usr/bin/perl" dev="dm-0" ino=XXX scontext=system_u:system_r:nagios_mail_plugin_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=file permissive=0
Environment
- Red Hat Enterprise Linux 7.8
- kernel-3.10.0-1127 and later
- nagios
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.