pam_abl selinux problem

Nicolas Mailhot nicolas.mailhot at laposte.net
Sat Nov 5 09:41:12 UTC 2005


Hi,

Following a thread on the fedora-extra list about which tool in FE
should be used to protect against sshd brute-force attacks I installed
pam_abl on my fedora devel box. Pam_abl is a security module that checks
every login attempt against user and host blacklists, and automatically
fill these lists after too frequent login failures.

Unfortunately it seems the devel security policies are not nice to
pam_abl, so it doesn't work :

Nov  5 10:27:02 rousalka pam_abl[3917]: Permission denied (13) while
opening or creating database

I've posted the relevant details (full audit logs...) in
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=172496

Could someone more qualified than me take a peek at them ?

-- 
Nicolas Mailhot
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 197 bytes
Desc: Ceci est une partie de message num?riquement sign?e
URL: <http://listman.redhat.com/archives/fedora-selinux-list/attachments/20051105/147ab676/attachment.sig>


More information about the fedora-selinux-list mailing list