Ahoy!

 

Filed https://bugzilla.redhat.com/show_bug.cgi?id=1144539 , ARGH!

 

Cap’n Y.

 

 

(Ay, it’s Talk like a pirate day)

 

 

 

From: Kaul, Yaniv
Sent: Thursday, September 18, 2014 9:01 PM
To: rdo-list@redhat.com
Subject: selinux preventing Horizon access?

 

IceHouse / CentOS 7- after reboot post install.

 

type=AVC msg=audit(1411063019.099:1848): avc:  denied  { name_connect } for  pid=5684 comm="httpd" dest=8776 scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket

 

 

getenforce Permissive solved it.

 

[root@lgdrm403 httpd(keystone_admin)]# rpm -qa |grep -E "openstack|selinux"

openstack-utils-2014.1-3.el7.noarch

selinux-policy-targeted-3.12.1-153.el7_0.10.noarch

openstack-nova-cert-2014.1.2-1.el7.centos.noarch

python-django-openstack-auth-1.1.5-1.el7.noarch

libselinux-2.2.2-6.el7.x86_64

openstack-glance-2014.1.2-4.el7.centos.noarch

openstack-packstack-puppet-2014.1.1-0.28.dev1238.el7.noarch

openstack-nova-novncproxy-2014.1.2-1.el7.centos.noarch

openstack-dashboard-2014.1.2-2.el7.centos.noarch

openstack-cinder-2014.1-2.el7.noarch

libselinux-utils-2.2.2-6.el7.x86_64

openstack-nova-console-2014.1.2-1.el7.centos.noarch

openstack-keystone-2014.1.2.1-1.el7.centos.noarch

libselinux-python-2.2.2-6.el7.x86_64

openstack-puppet-modules-2014.1-23.el7.noarch

libselinux-ruby-2.2.2-6.el7.x86_64

openstack-nova-api-2014.1.2-1.el7.centos.noarch

openstack-nova-compute-2014.1.2-1.el7.centos.noarch

openstack-nova-conductor-2014.1.2-1.el7.centos.noarch

openstack-nova-scheduler-2014.1.2-1.el7.centos.noarch

openstack-packstack-2014.1.1-0.28.dev1238.el7.noarch

selinux-policy-3.12.1-153.el7_0.10.noarch

openstack-selinux-0.5.15-1.el7ost.noarch

openstack-nova-common-2014.1.2-1.el7.centos.noarch

openstack-nova-network-2014.1.2-1.el7.centos.noarch