How to add applications in allow list using fapolicyd in RHEL ?
Issue
-
Why is the
fapolicydservice blocking command execution in RHEL? -
When
fapolicydis running, the third party application commands fails to execute. However the third party application functions when thefapolicydservice is stopped. -
User cannot execute operations (e.g. read) on certain files even though the ownership and permissions appear to be correct. Instead, user receives an 'Operation not permitted' message.
-
How to add a binary such as
/tmp/lsor binaries in directory/tmp/in allow list throughfapolicydwhen the debug output is reporting deny_audit events as shown as below :# cat fapolicy.output | grep 'deny_audit' ... rule=13 dec=deny_audit perm=execute auid=0 pid=6855 exe=/usr/bin/bash : path=/tmp/ls ftype=application/x-executable trust=0
Environment
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- fapolicyd
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.