• Recent
  • Unsolved
  • Tags
  • Popular
  • Users
  • Groups
  • Search
  • Register
  • Login
  • Recent
  • Unsolved
  • Tags
  • Popular
  • Users
  • Groups
  • Search
  • Register
  • Login

Selinux policy fail to mount image folder

Scheduled Pinned Locked Moved
General
4
6
1.9k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Z
    zacksiga
    last edited by Jan 24, 2017, 12:55 PM

    Re: SELinux Policy
    I was try incorporated selinux policy on my Fedora 25, everything seem to go well when i install the selinux policy, no error. But every time I go to capture image it fail to mount the image folder and capture of image fails. My setup has the upto date fog through github, and for image folder I have as secondary drive format in ntfs. I am wondering if the ntfs format has anything to do with this problem. The minute I disable selinux everything is working with no problem, I would like to run fog with selinux enforcing.

    1 Reply Last reply Reply Quote 0
    • G
      george1421 Moderator
      last edited by george1421 Jan 24, 2017, 7:53 AM Jan 24, 2017, 1:50 PM

      We had a discussion a while ago regarding the firewall settings [https://forums.fogproject.org/topic/6162/firewall-configuration] but I don’t think anyone has walked into the selinux area. The easiest answer is to just turn it off.

      But in some environments that isn’t possible. What I would recommend you do is switch selinux into permissive, reboot then run FOG through its paces. Once you have collected the required log entries then run the utility <name missing a the moment> to create a profile for fog. I’m suspecting that the /images directory is missing the flag for nfs connection.

      <edit> not the command I’m thinking of but this will report what selinux is blocking sealert -a /var/log/audit/audit.log </edit>

      Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG!

      1 Reply Last reply Reply Quote 0
      • W
        Wayne Workman
        last edited by Wayne Workman Jan 24, 2017, 7:57 AM Jan 24, 2017, 1:56 PM

        This is the best video I know of on the net regarding the subject. You will have to fine-tune SELinux, you can’t use the defaults with fog, they don’t work. If you have luck, please do share your work. Also here’s a thread on the topic: https://forums.fogproject.org/topic/6154/selinux-policy

        https://www.youtube.com/watch?v=MxjenQ31b70

        Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG!
        Daily Clean Installation Results:
        https://fogtesting.fogproject.us/
        FOG Reporting:
        https://fog-external-reporting-results.fogproject.us/

        1 Reply Last reply Reply Quote 0
        • Z
          zacksiga
          last edited by Jan 25, 2017, 1:40 PM

          Sorry for the late reply, I was actually think the same thing and I will give that a try and see what happens.

          1 Reply Last reply Reply Quote 0
          • J
            Joe Schmitt Senior Developer
            last edited by Jan 25, 2017, 2:53 PM

            @zacksiga If you’re willing to have your server run SEPermissive for a little bit, I can assist with creating a policy from the collected data, and if it works I’ll update our main repository with the new policy.

            Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG! Get in contact with me (chat bubble in the top right corner) if you want to join in.

            Z 1 Reply Last reply Jan 25, 2017, 2:55 PM Reply Quote 1
            • Z
              zacksiga @Joe Schmitt
              last edited by zacksiga Jan 25, 2017, 8:56 AM Jan 25, 2017, 2:55 PM

              @Joe-Schmitt I have no problem with that. Anything to help fog with

              1 Reply Last reply Reply Quote 0
              • 1 / 1
              1 / 1
              • First post
                6/6
                Last post

              155

              Online

              12.1k

              Users

              17.3k

              Topics

              155.3k

              Posts
              Copyright © 2012-2024 FOG Project