[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[postfix-jp: 3137] audit エラーについて



オカムラと申します。

クライアントからメールが送信されたタイミングで、サーバに
下記のような
エラーが表示されます。
※他のタイミングでもエラーが表示されますが、何と紐づいて
いるか分かりません。
ネットで調べるとSELinuxを利用しているからという情報があ
りますが、Offにしています。
# getenforce
Permissive

どういった原因が考えられるでしょうか?

# printk: 3 messages suppressed.
audit(1424175077.349:189): avc:  denied  { search } for 
pid=11558 comm="smtpd" name="mysql" dev=dm-0 ino=195037
scontext=root:system_r:postfix_smtpd_t:s0
tcontext=system_u:object_r:mysqld_db_t:s0 tclass=dir
audit(1424175077.349:190): avc:  denied  { connectto } for
 pid=11558 comm="smtpd" path="/var/lib/mysql/mysql.sock"
scontext=root:system_r:postfix_smtpd_t:s0
tcontext=root:system_r:mysqld_t:s0
tclass=unix_stream_socket
audit(1424175077.437:191): avc:  denied  { search } for 
pid=11564 comm="cleanup" name="mysql" dev=dm-0 ino=195037
scontext=root:system_r:postfix_cleanup_t:s0
tcontext=system_u:object_r:mysqld_db_t:s0 tclass=dir
audit(1424175077.437:192): avc:  denied  { write } for 
pid=11564 comm="cleanup" name="mysql.sock" dev=dm-0
ino=194988 scontext=root:system_r:postfix_cleanup_t:s0
tcontext=root:object_r:mysqld_var_run_t:s0
tclass=sock_file
audit(1424175077.437:193): avc:  denied  { connectto } for
 pid=11564 comm="cleanup" path="/var/lib/mysql/mysql.sock"
scontext=root:system_r:postfix_cleanup_t:s0
tcontext=root:system_r:mysqld_t:s0
tclass=unix_stream_socket
audit(1424175077.469:194): avc:  denied  { getattr } for 
pid=11564 comm="cleanup"
path="/usr/share/mysql/charsets/Index.xml" dev=dm-0
ino=493262 scontext=root:system_r:postfix_cleanup_t:s0
tcontext=system_u:object_r:usr_t:s0 tclass=file
audit(1424175077.469:195): avc:  denied  { read } for 
pid=11564 comm="cleanup" name="Index.xml" dev=dm-0
ino=493262 scontext=root:system_r:postfix_cleanup_t:s0
tcontext=system_u:object_r:usr_t:s0 tclass=file
audit(1424175077.549:196): avc:  denied  { search } for 
pid=11567 comm="virtual" name="mysql" dev=dm-0 ino=195037
scontext=root:system_r:postfix_virtual_t:s0
tcontext=system_u:object_r:mysqld_db_t:s0 tclass=dir
audit(1424175077.549:197): avc:  denied  { write } for 
pid=11567 comm="virtual" name="mysql.sock" dev=dm-0
ino=194988 scontext=root:system_r:postfix_virtual_t:s0
tcontext=root:object_r:mysqld_var_run_t:s0
tclass=sock_file
audit(1424175077.549:198): avc:  denied  { connectto } for
 pid=11567 comm="virtual" path="/var/lib/mysql/mysql.sock"
scontext=root:system_r:postfix_virtual_t:s0
tcontext=root:system_r:mysqld_t:s0
tclass=unix_stream_socket

参考になるか分かりませんが、postconf -nの結果は下記にな
ります。

alias_database = hash:/etc/aliases
alias_maps = hash:/etc/aliases
command_directory = /usr/sbin
config_directory = /etc/postfix
daemon_directory = /usr/libexec/postfix
debug_peer_level = 2
home_mailbox = Maildir/
html_directory = no
inet_interfaces = all
local_transport = virtual
mail_owner = postfix
mailbox_size_limit = 51200000
mailq_path = /usr/bin/mailq.postfix
manpage_directory = /usr/share/man
message_size_limit = 10240000
mydestination = 
mydomain = example.jp
myhostname = mail.example.jp
mynetworks = 192.168.1.0/24, 127.0.0.0/8
newaliases_path = /usr/bin/newaliases.postfix
queue_directory = /var/spool/postfix
readme_directory =
/usr/share/doc/postfix-2.3.3/README_FILES
relay_domains = $mydestination
sample_directory = /usr/share/doc/postfix-2.3.3/samples
sendmail_path = /usr/sbin/sendmail
setgid_group = postdrop
unknown_local_recipient_reject_code = 550
virtual_alias_domains = $virtual_alias_maps
virtual_alias_maps =
mysql:/etc/postfix/mysql_virtual_alias_maps.cf
virtual_gid_maps = static:10000
virtual_mailbox_base = /usr/local/virtual
virtual_mailbox_domains =
mysql:/etc/postfix/mysql_virtual_domains_maps.cf
virtual_mailbox_limit = 51200000
virtual_mailbox_limit_inbox = yes
virtual_mailbox_limit_maps = hash:/etc/postfix/vquota
virtual_mailbox_limit_override = yes
virtual_mailbox_maps =
mysql:/etc/postfix/mysql_virtual_mailbox_maps.cf
virtual_minimum_uid = 10000
virtual_overquota_bounce = yes
virtual_transport = virtual
virtual_uid_maps = static:10000


--------------------------------------
Enjoy MLB with MAJOR.JP! Ichiro, Matsuzaka, Matsui, and more!
http://pr.mail.yahoo.co.jp/mlb/

_______________________________________________
Postfix-jp-list mailing list
Postfix-jp-list@xxxxxxxxxxxxxxxxxxxx
http://lists.sourceforge.jp/mailman/listinfo/postfix-jp-list

Follow-Ups
[postfix-jp: 3138] Re: audit エラーについて, YAMAMOTO Hiroshi

[検索ページ] [Postfix-JP ML Home]