'net ads keytab create' command doesn't create /etc/krb5.keytab file when selinux is enabled
Issue
- If selinux is running in enforcing mode then it doesn't allow to create /etc/krb5.keytab file using "net ads keytab create -U administrator" command. After adding selinux policy by Audit2allow command, it works fine.
type=AVC msg=audit(1292874539.171:2339): avc: denied { getattr } for pid=16228 comm="net" path="/etc/krb5.keytab" dev=dm-0 ino=1231620 scontext=root:system_r:samba_net_t:s0-s0:c0.c1023 tcontext=system_u:object_r:krb5_keytab_t:s0 tclass=file
Environment
- Red Hat Enterprise Linux 5.5
- selinux-policy-2.4.6-279.el5
- samba-3.0.33-3.29.el5_5.1
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.