Paul Howarth wrote:
Turn off the dontaudit rules: # semodule -DBYou should then see the AVCs and be able to generate the policy module you need.You can then turn back on the dontaduit rules: # semodule -B
I don't have dontaudit turned on to begin with. As I mentioned, I *do* see AVCs for other selinux problems.
For this particular problem, I do *not* see AVCs. However, when I set selinux to Permissive, it works. So I think it's selinux-related, but there are not AVCs to give me clues.
johnn