audisp-remote failed to send message via KRB5 under SELinux

Solution Verified - Updated -

Issue

  • audisp-remote worked when SELinux is disabled or permissive, but failed when SELinux is enforced
  • journalctl -u auditd -g GSS reported:

    audisp-remote[123456]: GSS error: decrypting message: A required input parameter could not be read
    audisp-remote[123456]: GSS error: decrypting message: No context has been established
    

Environment

  • Red Hat Enterprise Linux 9
  • Red Hat Enterprise Linux 8
  • Red Hat Enterprise Linux 7
  • auditd
    • audisp-remote setup and worked when SELinux is disabled or permissive

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content