[Rdo-list] selinux preventing Horizon access?

Kaul, Yaniv Yaniv.Kaul at emc.com
Fri Sep 19 16:56:45 UTC 2014


Ahoy!

Filed https://bugzilla.redhat.com/show_bug.cgi?id=1144539 , ARGH!

Cap'n Y.


(Ay, it's Talk like a pirate day)



From: Kaul, Yaniv
Sent: Thursday, September 18, 2014 9:01 PM
To: rdo-list at redhat.com
Subject: selinux preventing Horizon access?

IceHouse / CentOS 7- after reboot post install.

type=AVC msg=audit(1411063019.099:1848): avc:  denied  { name_connect } for  pid=5684 comm="httpd" dest=8776 scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket


getenforce Permissive solved it.

[root at lgdrm403 httpd(keystone_admin)]# rpm -qa |grep -E "openstack|selinux"
openstack-utils-2014.1-3.el7.noarch
selinux-policy-targeted-3.12.1-153.el7_0.10.noarch
openstack-nova-cert-2014.1.2-1.el7.centos.noarch
python-django-openstack-auth-1.1.5-1.el7.noarch
libselinux-2.2.2-6.el7.x86_64
openstack-glance-2014.1.2-4.el7.centos.noarch
openstack-packstack-puppet-2014.1.1-0.28.dev1238.el7.noarch
openstack-nova-novncproxy-2014.1.2-1.el7.centos.noarch
openstack-dashboard-2014.1.2-2.el7.centos.noarch
openstack-cinder-2014.1-2.el7.noarch
libselinux-utils-2.2.2-6.el7.x86_64
openstack-nova-console-2014.1.2-1.el7.centos.noarch
openstack-keystone-2014.1.2.1-1.el7.centos.noarch
libselinux-python-2.2.2-6.el7.x86_64
openstack-puppet-modules-2014.1-23.el7.noarch
libselinux-ruby-2.2.2-6.el7.x86_64
openstack-nova-api-2014.1.2-1.el7.centos.noarch
openstack-nova-compute-2014.1.2-1.el7.centos.noarch
openstack-nova-conductor-2014.1.2-1.el7.centos.noarch
openstack-nova-scheduler-2014.1.2-1.el7.centos.noarch
openstack-packstack-2014.1.1-0.28.dev1238.el7.noarch
selinux-policy-3.12.1-153.el7_0.10.noarch
openstack-selinux-0.5.15-1.el7ost.noarch
openstack-nova-common-2014.1.2-1.el7.centos.noarch
openstack-nova-network-2014.1.2-1.el7.centos.noarch
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rdoproject.org/pipermail/dev/attachments/20140919/4267aef2/attachment.html>


More information about the dev mailing list