{"id":127,"date":"2008-05-30T06:59:48","date_gmt":"2008-05-30T14:59:48","guid":{"rendered":"http:\/\/jaredrobinson.com\/blog\/?p=127"},"modified":"2009-07-10T22:36:01","modified_gmt":"2009-07-11T04:36:01","slug":"nomachine-nx-fedora-9-and-selinux","status":"publish","type":"post","link":"https:\/\/jaredrobinson.com\/blog\/nomachine-nx-fedora-9-and-selinux\/","title":{"rendered":"NoMachine NX, Fedora 9 and SELinux"},"content":{"rendered":"<p>I upgraded from Fedora 7 to Fedora 9 using [preupgrade](http:\/\/fedoraproject.org\/wiki\/PreUpgrade), and then I couldn&#8217;t connect to the [NoMachine NX Server](http:\/\/www.nomachine.com\/). It&#8217;s due to SELinux, again (I [wrote about this earlier](http:\/\/jaredrobinson.com\/blog\/?p=89)). The approach to solve it is still the same, although the policy is different:<\/p>\n<p>Here&#8217;s what my audit.log messages looked like:<\/p>\n<p>    May 30 07:48:03 localhost kernel: type=1400 audit(1212155283.470:7): avc:  denied  { getattr } for  pid=876 \\<br \/>\n    comm=&#8221;sshd&#8221; path=&#8221;\/usr\/NX\/home\/nx\/.ssh\/authorized_keys2&#8243; dev=sda2 ino=70976 \\<br \/>\n    scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:usr_t:s0 tclass=file \\<br \/>\n    May 30 08:22:35 localhost kernel: type=1400 audit(1212157355.873:9): avc:  denied  { read } for  pid=872 \\<br \/>\n    comm=&#8221;sshd&#8221; name=&#8221;authorized_keys2&#8243; dev=sda2 ino=70976 \\<br \/>\n    scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:usr_t:s0 tclass=file<\/p>\n<p>Here&#8217;s how I created and inserted the policy:<\/p>\n<p>    cd \/etc\/selinux<br \/>\n    cat \/var\/log\/audit\/audit.log | audit2allow -M nx<br \/>\n    semodule -i nx.pp<\/p>\n<p>And here&#8217;s the nx.te file:<\/p>\n<p>    module nx 1.0;<br \/>\n    require {<br \/>\n        type sshd_t;<br \/>\n        type usr_t;<br \/>\n        class file { read getattr };<br \/>\n    }<br \/>\n    #============= sshd_t ==============<br \/>\n    allow sshd_t usr_t:file { read getattr };<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I upgraded from Fedora 7 to Fedora 9 using [preupgrade](http:\/\/fedoraproject.org\/wiki\/PreUpgrade), and then I couldn&#8217;t connect to the [NoMachine NX Server](http:\/\/www.nomachine.com\/). It&#8217;s due to SELinux, again (I [wrote about this earlier](http:\/\/jaredrobinson.com\/blog\/?p=89)). The approach to solve it is still the same, although the policy is different: Here&#8217;s what my audit.log messages looked like: May 30 07:48:03 localhost &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/jaredrobinson.com\/blog\/nomachine-nx-fedora-9-and-selinux\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;NoMachine NX, Fedora 9 and SELinux&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,17],"tags":[],"class_list":["post-127","post","type-post","status-publish","format-standard","hentry","category-fedora","category-tech"],"_links":{"self":[{"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/posts\/127","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/comments?post=127"}],"version-history":[{"count":12,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/posts\/127\/revisions"}],"predecessor-version":[{"id":427,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/posts\/127\/revisions\/427"}],"wp:attachment":[{"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/media?parent=127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/categories?post=127"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/tags?post=127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}