Project

General

Profile

Tâche #17611

Scénario #17544: Le module Seth doit respecter le mode de fonctionnement cible

Le fichier /etc/apparmor.d/local/usr.sbin.ntpd n'est pas pris en compte

Added by Klaas TJEBBES over 3 years ago. Updated over 3 years ago.

Status:
Fermé
Priority:
Normal
Assigned To:
Start date:
10/17/2016
Due date:
% Done:

100%

Estimated time:
1.00 h
Spent time:
Remaining (hours):
0.0

Description


journalctl -ex |grep ntp -i
oct. 18 12:20:13 dc1 audit32272: AVC apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/var/lib/samba/ntp_signd/socket" pid=32272 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=108 ouid=0
oct. 18 12:20:13 dc1 kernel: audit: type=1400 audit(1476786013.018:276): apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/var/lib/samba/ntp_signd/socket" pid=32272 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=108 ouid=0

Alors que si on déplace les lignes contenu dans ce fichier dans :
/etc/apparmor.d/usr.sbin.ntpd
l'erreur disparaît.

History

#1 Updated by Klaas TJEBBES over 3 years ago

log/rsyslog/local/kernel/kernel.notice.log:2016-10-18T17:12:51.234387+02:00 dc2.ac-test.lan kernel: [86761.603364] audit: type=1400 audit(1476803571.229:32): apparmor="STATUS" operation="profile_load" info="profile can not be replaced" error=-17 profile="unconfined" name="/usr/sbin/ntpd" pid=21720 comm="apparmor_parser"

#2 Updated by Klaas TJEBBES over 3 years ago

root@dc2:~# apparmor_status
apparmor module is loaded.
7 profiles are loaded.
7 profiles are in enforce mode.
[...]
0 profiles are in complain mode.
1 processes have profiles defined.
1 processes are in enforce mode.
/usr/sbin/ntpd (30521)

#3 Updated by Klaas TJEBBES over 3 years ago

  • Estimated time set to 0.00 h
  • Remaining (hours) set to 0.0

#4 Updated by Klaas TJEBBES over 3 years ago

  • Status changed from Nouveau to En cours

#5 Updated by Klaas TJEBBES over 3 years ago

  • Assigned To set to Klaas TJEBBES

#6 Updated by Scrum Master over 3 years ago

  • Status changed from En cours to Fermé

#7 Updated by Joël Cuissinat over 3 years ago

  • Estimated time changed from 0.00 h to 1.00 h

#8 Updated by Joël Cuissinat over 3 years ago

  • % Done changed from 0 to 100

Also available in: Atom PDF