[Rdo-list] selinux preventing Horizon access?

Kaul, Yaniv Yaniv.Kaul at emc.com
Thu Sep 18 18:00:59 UTC 2014


IceHouse / CentOS 7- after reboot post install.

type=AVC msg=audit(1411063019.099:1848): avc:  denied  { name_connect } for  pid=5684 comm="httpd" dest=8776 scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket


getenforce Permissive solved it.

[root at lgdrm403 httpd(keystone_admin)]# rpm -qa |grep -E "openstack|selinux"
openstack-utils-2014.1-3.el7.noarch
selinux-policy-targeted-3.12.1-153.el7_0.10.noarch
openstack-nova-cert-2014.1.2-1.el7.centos.noarch
python-django-openstack-auth-1.1.5-1.el7.noarch
libselinux-2.2.2-6.el7.x86_64
openstack-glance-2014.1.2-4.el7.centos.noarch
openstack-packstack-puppet-2014.1.1-0.28.dev1238.el7.noarch
openstack-nova-novncproxy-2014.1.2-1.el7.centos.noarch
openstack-dashboard-2014.1.2-2.el7.centos.noarch
openstack-cinder-2014.1-2.el7.noarch
libselinux-utils-2.2.2-6.el7.x86_64
openstack-nova-console-2014.1.2-1.el7.centos.noarch
openstack-keystone-2014.1.2.1-1.el7.centos.noarch
libselinux-python-2.2.2-6.el7.x86_64
openstack-puppet-modules-2014.1-23.el7.noarch
libselinux-ruby-2.2.2-6.el7.x86_64
openstack-nova-api-2014.1.2-1.el7.centos.noarch
openstack-nova-compute-2014.1.2-1.el7.centos.noarch
openstack-nova-conductor-2014.1.2-1.el7.centos.noarch
openstack-nova-scheduler-2014.1.2-1.el7.centos.noarch
openstack-packstack-2014.1.1-0.28.dev1238.el7.noarch
selinux-policy-3.12.1-153.el7_0.10.noarch
openstack-selinux-0.5.15-1.el7ost.noarch
openstack-nova-common-2014.1.2-1.el7.centos.noarch
openstack-nova-network-2014.1.2-1.el7.centos.noarch
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rdoproject.org/pipermail/dev/attachments/20140918/1c0b516f/attachment.html>


More information about the dev mailing list