Re: R: Re: R: Re: Samba misconfiguration

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 02/23/2011 05:43 PM, antonio montagnani wrote:
> Daniel J Walsh ha scritto / said the following    il giorno/on 
> 23/02/2011 23:17:
> On 02/23/2011 04:52 PM, antonio montagnani wrote:
>>>> Daniel J Walsh ha scritto / said the following    il giorno/on
>>>> 23/02/2011 22:18:
>>>>>
>>>>
>>>> After my previous post, I went through man samba_selinux just after
>>>> dinner, and also samba.conf file, and I understood that I should have
>>>> done some homework on selinux labeling and so on :-) : What surprises me
>>>> that on a different box in my home selinux is enforced too, but samba is
>>>> working fine sharing folders, even if I didn't do my homework (i.e. no
>>>> tip&tricks).
>>>> The real difference between these two machines is a fresh installation
>>>> of F14 (that is having these problems) and an F14 as update (when Samba
>>>> was installed Selinux had been disabled).
>>>>
>>>> Set
>>>>
>>>> What do you suggest?? not a problem at home as I am working with Fedora
>>>> only, a problem if I want share folders in a Windows environment (this
>>>> is a laptop)
>>>>
>>>> When I try to connect to the to-be-shared folder I get (not completely sure)
>>>>
>>>>> type=ANOM_ABEND msg=audit(1298497182.397:43): auid=500 uid=500 gid=500 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 pid=4107 comm="gvfsd-smb-brows" sig=6
>>>>> type=USER_AUTH msg=audit(1298497753.618:44): user pid=4318 uid=0 auid=500 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:authentication acct="root" exe="/usr/sbin/userhelper" hostname=? addr=? terminal=pts/1 res=success'
>>>>> type=USER_ACCT msg=audit(1298497753.618:45): user pid=4318 uid=0 auid=500 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/userhelper" hostname=? addr=? terminal=pts/1 res=success'
>>>>> type=USER_START msg=audit(1298497753.790:46): user pid=4318 uid=0 auid=500 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/userhelper" hostname=? addr=? terminal=pts/1 res=success'
>>>>> type=CRED_ACQ msg=audit(1298497753.790:47): user pid=4318 uid=0 auid=500 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/userhelper" hostname=? addr=? terminal=pts/1 res=success'
>>>>> type=USER_END msg=audit(1298497814.426:48): user pid=4318 uid=0 auid=500 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/userhelper" hostname=? addr=? terminal=pts/1 res=success'
>>>>> type=CRED_DISP msg=audit(1298497814.427:49): user pid=4318 uid=0 auid=500 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/userhelper" hostname=? addr=? terminal=pts/1 res=success'
>>>>
>>>>
>>>> Tnx a lot for help
>>>>
>>>> Antonio M
>>>> Skype: amontag52
>>>>
>>>> Linux Fedora F14 (Laughlin) on Acer 5720
>>>>
>>>> http://lugsaronno.altervista.org
>>>> www.campingmonterosa.com
>>>> www.studiodacolpaloschi.it
>>>>
>>>>
>>>>
> Those are not error messages.
> 
> What directories are you trying to share?
> 
> 

> is this more interesting??

> [2011/02/23 22:30:22.185337,  0] smbd/service.c:942(make_connection_snum)
>    Can't become connected user!
> [2011/02/23 22:30:26.167088,  1] smbd/service.c:1070(make_connection_snum)
>    acer (::ffff:192.168.1.20) connect to service Musica initially as 
> user antonio (uid=500, gid=500) (pid 3826)
> [2011/02/23 22:39:42.765904,  0] lib/util_sock.c:474(read_fd_with_timeout)
> [2011/02/23 22:39:42.767077,  0] 
> lib/util_sock.c:1432(get_peer_addr_internal)
>    getpeername failed. Error was Il socket di destinazione non è connesso
>    read_fd_with_timeout: client 0.0.0.0 read error = Connessione 
> interrotta dal corrispondente.

I think the easiest is

setsebool -P samba_enabe_home_dirs 1

You also have booleans
samba_export_all_rw
samba_export_all_ro

To share everything.

You could also label the content as samba_share_t.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/

iEYEARECAAYFAk1ljtsACgkQrlYvE4MpobNQxwCeLbLOWu0l4lxvPoI0ejA9eWwP
+0IAoLYYwl12uYntxdWZGA8lDAZ8qk/z
=9Q6y
-----END PGP SIGNATURE-----
-- 
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines



[Index of Archives]     [Current Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [Yosemite Photos]     [KDE Users]     [Fedora Tools]     [Fedora Docs]

  Powered by Linux