Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [root@vm1 ~]# df -h
- Filesystem Size Used Avail Use% Mounted on
- /dev/sda1 10G 1.5G 8.6G 15% /
- devtmpfs 287M 0 287M 0% /dev
- tmpfs 294M 0 294M 0% /dev/shm
- tmpfs 294M 4.4M 290M 2% /run
- tmpfs 294M 0 294M 0% /sys/fs/cgroup
- tmpfs 59M 0 59M 0% /run/user/1001
- [root@vm1 ~]# yum update
- Loaded plugins: fastestmirror
- Determining fastest mirrors
- epel/x86_64/metalink | 17 kB 00:00
- * base: mirror.steadfastnet.com
- * epel: mirror.steadfastnet.com
- * extras: ftpmirror.your.org
- * updates: mirrors.liquidweb.com
- base | 3.6 kB 00:00
- epel | 3.2 kB 00:00
- extras | 3.4 kB 00:00
- google-cloud-compute/signature | 454 B 00:00
- google-cloud-compute/signature | 1.8 kB 00:00 !!!
- google-cloud-sdk/signature | 454 B 00:00
- google-cloud-sdk/signature | 1.4 kB 00:00 !!!
- updates | 3.4 kB 00:00
- (1/10): base/7/x86_64/group_gz | 166 kB 00:00
- (2/10): epel/x86_64/group_gz | 88 kB 00:00
- (3/10): epel/x86_64/updateinfo | 941 kB 00:00
- (4/10): epel/x86_64/primary | 3.6 MB 00:00
- (5/10): extras/7/x86_64/primary_db | 187 kB 00:00
- (6/10): base/7/x86_64/primary_db | 5.9 MB 00:00
- (7/10): google-cloud-compute/updateinfo | 1.1 kB 00:00
- (8/10): google-cloud-compute/primary | 3.6 kB 00:00
- (9/10): google-cloud-sdk/primary | 45 kB 00:00
- (10/10): updates/7/x86_64/primary_db | 5.2 MB 00:00
- epel 12672/12672
- google-cloud-compute 10/10
- google-cloud-sdk 278/278
- Resolving Dependencies
- --> Running transaction check
- ---> Package audit.x86_64 0:2.8.1-3.el7 will be updated
- ---> Package audit.x86_64 0:2.8.1-3.el7_5.1 will be an update
- ---> Package audit-libs.x86_64 0:2.8.1-3.el7 will be updated
- ---> Package audit-libs.x86_64 0:2.8.1-3.el7_5.1 will be an update
- ---> Package audit-libs-python.x86_64 0:2.8.1-3.el7 will be updated
- ---> Package audit-libs-python.x86_64 0:2.8.1-3.el7_5.1 will be an update
- ---> Package bind-libs-lite.x86_64 32:9.9.4-61.el7 will be updated
- ---> Package bind-libs-lite.x86_64 32:9.9.4-61.el7_5.1 will be an update
- ---> Package bind-license.noarch 32:9.9.4-61.el7 will be updated
- ---> Package bind-license.noarch 32:9.9.4-61.el7_5.1 will be an update
- ---> Package dracut.x86_64 0:033-535.el7 will be updated
- ---> Package dracut.x86_64 0:033-535.el7_5.1 will be an update
- ---> Package dracut-config-rescue.x86_64 0:033-535.el7 will be updated
- ---> Package dracut-config-rescue.x86_64 0:033-535.el7_5.1 will be an update
- ---> Package google-cloud-sdk.noarch 0:212.0.0-1.el7 will be updated
- ---> Package google-cloud-sdk.noarch 0:215.0.0-1.el7 will be an update
- ---> Package initscripts.x86_64 0:9.49.41-1.el7 will be updated
- ---> Package initscripts.x86_64 0:9.49.41-1.el7_5.1 will be an update
- ---> Package kpartx.x86_64 0:0.4.9-119.el7 will be updated
- ---> Package kpartx.x86_64 0:0.4.9-119.el7_5.1 will be an update
- ---> Package libblkid.x86_64 0:2.23.2-52.el7 will be updated
- ---> Package libblkid.x86_64 0:2.23.2-52.el7_5.1 will be an update
- ---> Package libmount.x86_64 0:2.23.2-52.el7 will be updated
- ---> Package libmount.x86_64 0:2.23.2-52.el7_5.1 will be an update
- ---> Package libuuid.x86_64 0:2.23.2-52.el7 will be updated
- ---> Package libuuid.x86_64 0:2.23.2-52.el7_5.1 will be an update
- ---> Package mariadb-libs.x86_64 1:5.5.56-2.el7 will be updated
- ---> Package mariadb-libs.x86_64 1:5.5.60-1.el7_5 will be an update
- ---> Package qemu-guest-agent.x86_64 10:2.8.0-2.el7 will be updated
- ---> Package qemu-guest-agent.x86_64 10:2.8.0-2.el7_5.1 will be an update
- ---> Package selinux-policy.noarch 0:3.13.1-192.el7_5.4 will be updated
- ---> Package selinux-policy.noarch 0:3.13.1-192.el7_5.6 will be an update
- ---> Package selinux-policy-targeted.noarch 0:3.13.1-192.el7_5.4 will be updated
- ---> Package selinux-policy-targeted.noarch 0:3.13.1-192.el7_5.6 will be an upda te
- ---> Package systemd.x86_64 0:219-57.el7 will be updated
- ---> Package systemd.x86_64 0:219-57.el7_5.1 will be an update
- ---> Package systemd-libs.x86_64 0:219-57.el7 will be updated
- ---> Package systemd-libs.x86_64 0:219-57.el7_5.1 will be an update
- ---> Package systemd-sysv.x86_64 0:219-57.el7 will be updated
- ---> Package systemd-sysv.x86_64 0:219-57.el7_5.1 will be an update
- ---> Package tuned.noarch 0:2.9.0-1.el7 will be updated
- ---> Package tuned.noarch 0:2.9.0-1.el7_5.2 will be an update
- ---> Package util-linux.x86_64 0:2.23.2-52.el7 will be updated
- ---> Package util-linux.x86_64 0:2.23.2-52.el7_5.1 will be an update
- --> Finished Dependency Resolution
- Dependencies Resolved
- ================================================================================
- Package Arch Version Repository Size
- ================================================================================
- Updating:
- audit x86_64 2.8.1-3.el7_5.1 updates 247 k
- audit-libs x86_64 2.8.1-3.el7_5.1 updates 99 k
- audit-libs-python x86_64 2.8.1-3.el7_5.1 updates 75 k
- bind-libs-lite x86_64 32:9.9.4-61.el7_5.1 updates 734 k
- bind-license noarch 32:9.9.4-61.el7_5.1 updates 85 k
- dracut x86_64 033-535.el7_5.1 updates 325 k
- dracut-config-rescue x86_64 033-535.el7_5.1 updates 58 k
- google-cloud-sdk noarch 215.0.0-1.el7 google-cloud-sdk 28 M
- initscripts x86_64 9.49.41-1.el7_5.1 updates 437 k
- kpartx x86_64 0.4.9-119.el7_5.1 updates 76 k
- libblkid x86_64 2.23.2-52.el7_5.1 updates 178 k
- libmount x86_64 2.23.2-52.el7_5.1 updates 180 k
- libuuid x86_64 2.23.2-52.el7_5.1 updates 81 k
- mariadb-libs x86_64 1:5.5.60-1.el7_5 updates 758 k
- qemu-guest-agent x86_64 10:2.8.0-2.el7_5.1 updates 150 k
- selinux-policy noarch 3.13.1-192.el7_5.6 updates 453 k
- selinux-policy-targeted noarch 3.13.1-192.el7_5.6 updates 6.6 M
- systemd x86_64 219-57.el7_5.1 updates 5.0 M
- systemd-libs x86_64 219-57.el7_5.1 updates 402 k
- systemd-sysv x86_64 219-57.el7_5.1 updates 79 k
- tuned noarch 2.9.0-1.el7_5.2 updates 244 k
- util-linux x86_64 2.23.2-52.el7_5.1 updates 2.0 M
- Transaction Summary
- ================================================================================
- Upgrade 22 Packages
- Total download size: 46 M
- Is this ok [y/d/N]: y
- Downloading packages:
- Delta RPMs disabled because /usr/bin/applydeltarpm not installed.
- (1/22): audit-libs-2.8.1-3.el7_5.1.x86_64.rpm | 99 kB 00:00
- (2/22): audit-libs-python-2.8.1-3.el7_5.1.x86_64.rpm | 75 kB 00:00
- (3/22): bind-license-9.9.4-61.el7_5.1.noarch.rpm | 85 kB 00:00
- (4/22): audit-2.8.1-3.el7_5.1.x86_64.rpm | 247 kB 00:00
- (5/22): dracut-config-rescue-033-535.el7_5.1.x86_64.rpm | 58 kB 00:00
- (6/22): kpartx-0.4.9-119.el7_5.1.x86_64.rpm | 76 kB 00:00
- (7/22): initscripts-9.49.41-1.el7_5.1.x86_64.rpm | 437 kB 00:00
- (8/22): dracut-033-535.el7_5.1.x86_64.rpm | 325 kB 00:00
- (9/22): libmount-2.23.2-52.el7_5.1.x86_64.rpm | 180 kB 00:00
- (10/22): libblkid-2.23.2-52.el7_5.1.x86_64.rpm | 178 kB 00:00
- (11/22): bind-libs-lite-9.9.4-61.el7_5.1.x86_64.rpm | 734 kB 00:00
- (12/22): libuuid-2.23.2-52.el7_5.1.x86_64.rpm | 81 kB 00:00
- (13/22): mariadb-libs-5.5.60-1.el7_5.x86_64.rpm | 758 kB 00:00
- (14/22): selinux-policy-3.13.1-192.el7_5.6.noarch.rpm | 453 kB 00:00
- (15/22): systemd-libs-219-57.el7_5.1.x86_64.rpm | 402 kB 00:00
- (16/22): systemd-sysv-219-57.el7_5.1.x86_64.rpm | 79 kB 00:00
- (17/22): tuned-2.9.0-1.el7_5.2.noarch.rpm | 244 kB 00:00
- (18/22): systemd-219-57.el7_5.1.x86_64.rpm | 5.0 MB 00:00
- (19/22): selinux-policy-targeted-3.13.1-192.el7_5.6.noarch | 6.6 MB 00:00
- (20/22): util-linux-2.23.2-52.el7_5.1.x86_64.rpm | 2.0 MB 00:00
- (21/22): 654962a43cb6bc6b47bc312424410b7c203e1beb73386d868 | 28 MB 00:01
- (22/22): qemu-guest-agent-2.8.0-2.el7_5.1.x86_64.rpm | 150 kB 00:01
- --------------------------------------------------------------------------------
- Total 26 MB/s | 46 MB 00:01
- Running transaction check
- Running transaction test
- Transaction test succeeded
- Running transaction
- Updating : audit-libs-2.8.1-3.el7_5.1.x86_64 1/44
- Updating : libuuid-2.23.2-52.el7_5.1.x86_64 2/44
- Updating : libblkid-2.23.2-52.el7_5.1.x86_64 3/44
- Updating : libmount-2.23.2-52.el7_5.1.x86_64 4/44
- Updating : systemd-libs-219-57.el7_5.1.x86_64 5/44
- Updating : systemd-219-57.el7_5.1.x86_64 6/44
- Updating : util-linux-2.23.2-52.el7_5.1.x86_64 7/44
- Updating : systemd-sysv-219-57.el7_5.1.x86_64 8/44
- Updating : 32:bind-license-9.9.4-61.el7_5.1.noarch 9/44
- Updating : selinux-policy-3.13.1-192.el7_5.6.noarch 10/44
- Updating : kpartx-0.4.9-119.el7_5.1.x86_64 11/44
- Updating : dracut-033-535.el7_5.1.x86_64 12/44
- Updating : dracut-config-rescue-033-535.el7_5.1.x86_64 13/44
- Updating : selinux-policy-targeted-3.13.1-192.el7_5.6.noarch 14/44
- Updating : 32:bind-libs-lite-9.9.4-61.el7_5.1.x86_64 15/44
- Updating : audit-2.8.1-3.el7_5.1.x86_64 16/44
- Updating : initscripts-9.49.41-1.el7_5.1.x86_64 17/44
- Updating : tuned-2.9.0-1.el7_5.2.noarch 18/44
- Updating : 10:qemu-guest-agent-2.8.0-2.el7_5.1.x86_64 19/44
- Updating : audit-libs-python-2.8.1-3.el7_5.1.x86_64 20/44
- Updating : google-cloud-sdk-215.0.0-1.el7.noarch 21/44
- Updating : 1:mariadb-libs-5.5.60-1.el7_5.x86_64 22/44
- Cleanup : audit-2.8.1-3.el7.x86_64 23/44
- Cleanup : tuned-2.9.0-1.el7.noarch 24/44
- Cleanup : initscripts-9.49.41-1.el7.x86_64 25/44
- Cleanup : systemd-sysv-219-57.el7.x86_64 26/44
- Cleanup : dracut-config-rescue-033-535.el7.x86_64 27/44
- Cleanup : selinux-policy-targeted-3.13.1-192.el7_5.4.noarch 28/44
- Cleanup : dracut-033-535.el7.x86_64 29/44
- Cleanup : util-linux-2.23.2-52.el7.x86_64 30/44
- Cleanup : 10:qemu-guest-agent-2.8.0-2.el7.x86_64 31/44
- Cleanup : systemd-219-57.el7.x86_64 32/44
- Cleanup : libmount-2.23.2-52.el7.x86_64 33/44
- Cleanup : libblkid-2.23.2-52.el7.x86_64 34/44
- Cleanup : 32:bind-libs-lite-9.9.4-61.el7.x86_64 35/44
- Cleanup : audit-libs-python-2.8.1-3.el7.x86_64 36/44
- Cleanup : 32:bind-license-9.9.4-61.el7.noarch 37/44
- Cleanup : selinux-policy-3.13.1-192.el7_5.4.noarch 38/44
- Cleanup : google-cloud-sdk-212.0.0-1.el7.noarch 39/44
- Cleanup : audit-libs-2.8.1-3.el7.x86_64 40/44
- Cleanup : libuuid-2.23.2-52.el7.x86_64 41/44
- Cleanup : systemd-libs-219-57.el7.x86_64 42/44
- Cleanup : kpartx-0.4.9-119.el7.x86_64 43/44
- Cleanup : 1:mariadb-libs-5.5.56-2.el7.x86_64 44/44
- Verifying : initscripts-9.49.41-1.el7_5.1.x86_64 1/44
- Verifying : audit-libs-python-2.8.1-3.el7_5.1.x86_64 2/44
- Verifying : 1:mariadb-libs-5.5.60-1.el7_5.x86_64 3/44
- Verifying : audit-2.8.1-3.el7_5.1.x86_64 4/44
- Verifying : kpartx-0.4.9-119.el7_5.1.x86_64 5/44
- Verifying : 32:bind-libs-lite-9.9.4-61.el7_5.1.x86_64 6/44
- Verifying : 10:qemu-guest-agent-2.8.0-2.el7_5.1.x86_64 7/44
- Verifying : systemd-sysv-219-57.el7_5.1.x86_64 8/44
- Verifying : tuned-2.9.0-1.el7_5.2.noarch 9/44
- Verifying : selinux-policy-targeted-3.13.1-192.el7_5.6.noarch 10/44
- Verifying : libmount-2.23.2-52.el7_5.1.x86_64 11/44
- Verifying : selinux-policy-3.13.1-192.el7_5.6.noarch 12/44
- Verifying : systemd-219-57.el7_5.1.x86_64 13/44
- Verifying : systemd-libs-219-57.el7_5.1.x86_64 14/44
- Verifying : 32:bind-license-9.9.4-61.el7_5.1.noarch 15/44
- Verifying : libuuid-2.23.2-52.el7_5.1.x86_64 16/44
- Verifying : dracut-config-rescue-033-535.el7_5.1.x86_64 17/44
- Verifying : audit-libs-2.8.1-3.el7_5.1.x86_64 18/44
- Verifying : dracut-033-535.el7_5.1.x86_64 19/44
- Verifying : libblkid-2.23.2-52.el7_5.1.x86_64 20/44
- Verifying : util-linux-2.23.2-52.el7_5.1.x86_64 21/44
- Verifying : google-cloud-sdk-215.0.0-1.el7.noarch 22/44
- Verifying : selinux-policy-3.13.1-192.el7_5.4.noarch 23/44
- Verifying : libmount-2.23.2-52.el7.x86_64 24/44
- Verifying : audit-libs-2.8.1-3.el7.x86_64 25/44
- Verifying : libblkid-2.23.2-52.el7.x86_64 26/44
- Verifying : 1:mariadb-libs-5.5.56-2.el7.x86_64 27/44
- Verifying : kpartx-0.4.9-119.el7.x86_64 28/44
- Verifying : selinux-policy-targeted-3.13.1-192.el7_5.4.noarch 29/44
- Verifying : tuned-2.9.0-1.el7.noarch 30/44
- Verifying : dracut-033-535.el7.x86_64 31/44
- Verifying : util-linux-2.23.2-52.el7.x86_64 32/44
- Verifying : audit-2.8.1-3.el7.x86_64 33/44
- Verifying : audit-libs-python-2.8.1-3.el7.x86_64 34/44
- Verifying : systemd-219-57.el7.x86_64 35/44
- Verifying : systemd-sysv-219-57.el7.x86_64 36/44
- Verifying : 32:bind-license-9.9.4-61.el7.noarch 37/44
- Verifying : initscripts-9.49.41-1.el7.x86_64 38/44
- Verifying : dracut-config-rescue-033-535.el7.x86_64 39/44
- Verifying : systemd-libs-219-57.el7.x86_64 40/44
- Verifying : 10:qemu-guest-agent-2.8.0-2.el7.x86_64 41/44
- Verifying : google-cloud-sdk-212.0.0-1.el7.noarch 42/44
- Verifying : libuuid-2.23.2-52.el7.x86_64 43/44
- Verifying : 32:bind-libs-lite-9.9.4-61.el7.x86_64 44/44
- Updated:
- audit.x86_64 0:2.8.1-3.el7_5.1
- audit-libs.x86_64 0:2.8.1-3.el7_5.1
- audit-libs-python.x86_64 0:2.8.1-3.el7_5.1
- bind-libs-lite.x86_64 32:9.9.4-61.el7_5.1
- bind-license.noarch 32:9.9.4-61.el7_5.1
- dracut.x86_64 0:033-535.el7_5.1
- dracut-config-rescue.x86_64 0:033-535.el7_5.1
- google-cloud-sdk.noarch 0:215.0.0-1.el7
- initscripts.x86_64 0:9.49.41-1.el7_5.1
- kpartx.x86_64 0:0.4.9-119.el7_5.1
- libblkid.x86_64 0:2.23.2-52.el7_5.1
- libmount.x86_64 0:2.23.2-52.el7_5.1
- libuuid.x86_64 0:2.23.2-52.el7_5.1
- mariadb-libs.x86_64 1:5.5.60-1.el7_5
- qemu-guest-agent.x86_64 10:2.8.0-2.el7_5.1
- selinux-policy.noarch 0:3.13.1-192.el7_5.6
- selinux-policy-targeted.noarch 0:3.13.1-192.el7_5.6
- systemd.x86_64 0:219-57.el7_5.1
- systemd-libs.x86_64 0:219-57.el7_5.1
- systemd-sysv.x86_64 0:219-57.el7_5.1
- tuned.noarch 0:2.9.0-1.el7_5.2
- util-linux.x86_64 0:2.23.2-52.el7_5.1
- Complete!
- [root@vm1 ~]# getenforce
- Enforcing
- [root@vm1 ~]# firewall-cmd --state
- running
- [root@vm1 ~]# reboot
- Using username "snikolov-putty".
- Authenticating with public key ""
- Last login: Mon Sep 10 07:35:42 2018 from 15.195.179.254
- [snikolov-putty@vm1 ~]$ sudo su -
- Last login: Mon Sep 10 07:36:37 UTC 2018 on pts/0
- [root@vm1 ~]# vim /etc/hosts
- [root@vm1 ~]# yum install httpd mod_wsgi
- Loaded plugins: fastestmirror
- Loading mirror speeds from cached hostfile
- * base: mirror.steadfastnet.com
- * epel: mirror.steadfastnet.com
- * extras: ftpmirror.your.org
- * updates: mirrors.liquidweb.com
- Resolving Dependencies
- --> Running transaction check
- ---> Package httpd.x86_64 0:2.4.6-80.el7.centos.1 will be installed
- --> Processing Dependency: httpd-tools = 2.4.6-80.el7.centos.1 for package: httpd-2.4.6-80.el7.centos.1.x86_64
- --> Processing Dependency: /etc/mime.types for package: httpd-2.4.6-80.el7.centos.1.x86_64
- --> Processing Dependency: libaprutil-1.so.0()(64bit) for package: httpd-2.4.6-80.el7.centos.1.x86_64
- --> Processing Dependency: libapr-1.so.0()(64bit) for package: httpd-2.4.6-80.el7.centos.1.x86_64
- ---> Package mod_wsgi.x86_64 0:3.4-12.el7_0 will be installed
- --> Running transaction check
- ---> Package apr.x86_64 0:1.4.8-3.el7_4.1 will be installed
- ---> Package apr-util.x86_64 0:1.5.2-6.el7 will be installed
- ---> Package httpd-tools.x86_64 0:2.4.6-80.el7.centos.1 will be installed
- ---> Package mailcap.noarch 0:2.1.41-2.el7 will be installed
- --> Finished Dependency Resolution
- Dependencies Resolved
- =============================================================================================================================================================
- Package Arch Version Repository Size
- =============================================================================================================================================================
- Installing:
- httpd x86_64 2.4.6-80.el7.centos.1 updates 2.7 M
- mod_wsgi x86_64 3.4-12.el7_0 base 76 k
- Installing for dependencies:
- apr x86_64 1.4.8-3.el7_4.1 base 103 k
- apr-util x86_64 1.5.2-6.el7 base 92 k
- httpd-tools x86_64 2.4.6-80.el7.centos.1 updates 90 k
- mailcap noarch 2.1.41-2.el7 base 31 k
- Transaction Summary
- =============================================================================================================================================================
- Install 2 Packages (+4 Dependent packages)
- Total download size: 3.1 M
- Installed size: 10 M
- Is this ok [y/d/N]: y
- Downloading packages:
- (1/6): httpd-tools-2.4.6-80.el7.centos.1.x86_64.rpm | 90 kB 00:00:00
- (2/6): apr-1.4.8-3.el7_4.1.x86_64.rpm | 103 kB 00:00:00
- (3/6): mailcap-2.1.41-2.el7.noarch.rpm | 31 kB 00:00:00
- (4/6): apr-util-1.5.2-6.el7.x86_64.rpm | 92 kB 00:00:00
- (5/6): mod_wsgi-3.4-12.el7_0.x86_64.rpm | 76 kB 00:00:00
- (6/6): httpd-2.4.6-80.el7.centos.1.x86_64.rpm | 2.7 MB 00:00:00
- -------------------------------------------------------------------------------------------------------------------------------------------------------------
- Total 5.7 MB/s | 3.1 MB 00:00:00
- Running transaction check
- Running transaction test
- Transaction test succeeded
- Running transaction
- Installing : apr-1.4.8-3.el7_4.1.x86_64 1/6
- Installing : apr-util-1.5.2-6.el7.x86_64 2/6
- Installing : httpd-tools-2.4.6-80.el7.centos.1.x86_64 3/6
- Installing : mailcap-2.1.41-2.el7.noarch 4/6
- Installing : httpd-2.4.6-80.el7.centos.1.x86_64 5/6
- Installing : mod_wsgi-3.4-12.el7_0.x86_64 6/6
- Verifying : mod_wsgi-3.4-12.el7_0.x86_64 1/6
- Verifying : mailcap-2.1.41-2.el7.noarch 2/6
- Verifying : httpd-tools-2.4.6-80.el7.centos.1.x86_64 3/6
- Verifying : apr-util-1.5.2-6.el7.x86_64 4/6
- Verifying : httpd-2.4.6-80.el7.centos.1.x86_64 5/6
- Verifying : apr-1.4.8-3.el7_4.1.x86_64 6/6
- Installed:
- httpd.x86_64 0:2.4.6-80.el7.centos.1 mod_wsgi.x86_64 0:3.4-12.el7_0
- Dependency Installed:
- apr.x86_64 0:1.4.8-3.el7_4.1 apr-util.x86_64 0:1.5.2-6.el7 httpd-tools.x86_64 0:2.4.6-80.el7.centos.1 mailcap.noarch 0:2.1.41-2.el7
- Complete!
- [root@vm1 ~]# firewall-cmd --permanent --add-service=http
- success
- [root@vm1 ~]# firewall-cmd --reload
- success
- [root@vm1 ~]# cat /etc/hosts
- 127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
- ::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
- 10.128.0.2 vm1.c.sixth-wave-179410.internal vm1 # Added by Google
- 169.254.169.254 metadata.google.internal # Added by Google
- [root@vm1 ~]# curl http://vm1.c.sixth-wave-179410.internal
- curl: (7) Failed connect to vm1.c.sixth-wave-179410.internal:80; Connection refused
- [root@vm1 ~]# curl http://vm1.c.sixth-wave-179410.internal
- curl: (7) Failed connect to vm1.c.sixth-wave-179410.internal:80; Connection refused
- [root@vm1 ~]# ip a s
- 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
- link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
- inet 127.0.0.1/8 scope host lo
- valid_lft forever preferred_lft forever
- inet6 ::1/128 scope host
- valid_lft forever preferred_lft forever
- 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1460 qdisc pfifo_fast state UP group default qlen 1000
- link/ether 42:01:0a:80:00:02 brd ff:ff:ff:ff:ff:ff
- inet 10.128.0.2/32 brd 10.128.0.2 scope global noprefixroute dynamic eth0
- valid_lft 85694sec preferred_lft 85694sec
- inet6 fe80::4001:aff:fe80:2/64 scope link
- valid_lft forever preferred_lft forever
- [root@vm1 ~]# ping vm1.c.sixth-wave-179410.internal
- PING vm1.c.sixth-wave-179410.internal (10.128.0.2) 56(84) bytes of data.
- 64 bytes from vm1.c.sixth-wave-179410.internal (10.128.0.2): icmp_seq=1 ttl=64 time=0.046 ms
- 64 bytes from vm1.c.sixth-wave-179410.internal (10.128.0.2): icmp_seq=2 ttl=64 time=0.050 ms
- ^C
- --- vm1.c.sixth-wave-179410.internal ping statistics ---
- 2 packets transmitted, 2 received, 0% packet loss, time 999ms
- rtt min/avg/max/mdev = 0.046/0.048/0.050/0.002 ms
- [root@vm1 ~]# firewall-cmd --list-all
- trusted (active)
- target: ACCEPT
- icmp-block-inversion: no
- interfaces: eth0
- sources:
- services: http
- ports:
- protocols:
- masquerade: no
- forward-ports:
- source-ports:
- icmp-blocks:
- rich rules:
- [root@vm1 ~]# systemctl enable --now httpd
- Created symlink from /etc/systemd/system/multi-user.target.wants/httpd.service to /usr/lib/systemd/system/httpd.service.
- [root@vm1 ~]# curl http://vm1.c.sixth-wave-179410.internal
- <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd"><html><head>
- <meta http-equiv="content-type" content="text/html; charset=UTF-8">
- <title>Apache HTTP Server Test Page powered by CentOS</title>
- <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
- <!-- Bootstrap -->
- <link href="/noindex/css/bootstrap.min.css" rel="stylesheet">
- <link rel="stylesheet" href="noindex/css/open-sans.css" type="text/css" />
- <style type="text/css"><!--
- body {
- font-family: "Open Sans", Helvetica, sans-serif;
- font-weight: 100;
- color: #ccc;
- background: rgba(10, 24, 55, 1);
- font-size: 16px;
- }
- h2, h3, h4 {
- font-weight: 200;
- }
- h2 {
- font-size: 28px;
- }
- .jumbotron {
- margin-bottom: 0;
- color: #333;
- background: rgb(212,212,221); /* Old browsers */
- background: radial-gradient(ellipse at center top, rgba(255,255,255,1) 0%,rgba(174,174,183,1) 100%); /* W3C */
- }
- .jumbotron h1 {
- font-size: 128px;
- font-weight: 700;
- color: white;
- text-shadow: 0px 2px 0px #abc,
- 0px 4px 10px rgba(0,0,0,0.15),
- 0px 5px 2px rgba(0,0,0,0.1),
- 0px 6px 30px rgba(0,0,0,0.1);
- }
- .jumbotron p {
- font-size: 28px;
- font-weight: 100;
- }
- .main {
- background: white;
- color: #234;
- border-top: 1px solid rgba(0,0,0,0.12);
- padding-top: 30px;
- padding-bottom: 40px;
- }
- .footer {
- border-top: 1px solid rgba(255,255,255,0.2);
- padding-top: 30px;
- }
- --></style>
- </head>
- <body>
- <div class="jumbotron text-center">
- <div class="container">
- <h1>Testing 123..</h1>
- <p class="lead">This page is used to test the proper operation of the <a href="http://apache.org">Apache HTTP server</a> after it has been installed. If you can read this page it means that this site is working properly. This server is powered by <a href="http://centos.org">CentOS</a>.</p>
- </div>
- </div>
- <div class="main">
- <div class="container">
- <div class="row">
- <div class="col-sm-6">
- <h2>Just visiting?</h2>
- <p class="lead">The website you just visited is either experiencing problems or is undergoing routine maintenance.</p>
- <p>If you would like to let the administrators of this website know that you've seen this page instead of the page you expected, you should send them e-mail. In general, mail sent to the name "webmaster" and directed to the website's domain should reach the appropriate person.</p>
- <p>For example, if you experienced problems while visiting www.example.com, you should send e-mail to "webmaster@example.com".</p>
- </div>
- <div class="col-sm-6">
- <h2>Are you the Administrator?</h2>
- <p>You should add your website content to the directory <tt>/var/www/html/</tt>.</p>
- <p>To prevent this page from ever being used, follow the instructions in the file <tt>/etc/httpd/conf.d/welcome.conf</tt>.</p>
- <h2>Promoting Apache and CentOS</h2>
- <p>You are free to use the images below on Apache and CentOS Linux powered HTTP servers. Thanks for using Apache and CentOS!</p>
- <p><a href="http://httpd.apache.org/"><img src="images/apache_pb.gif" alt="[ Powered by Apache ]"></a> <a href="http://www.centos.org/"><img src="images/poweredby.png" alt="[ Powered by CentOS Linux ]" height="31" width="88"></a></p>
- </div>
- </div>
- </div>
- </div>
- </div>
- <div class="footer">
- <div class="container">
- <div class="row">
- <div class="col-sm-6">
- <h2>Important note:</h2>
- <p class="lead">The CentOS Project has nothing to do with this website or its content,
- it just provides the software that makes the website run.</p>
- <p>If you have issues with the content of this site, contact the owner of the domain, not the CentOS project.
- Unless you intended to visit CentOS.org, the CentOS Project does not have anything to do with this website,
- the content or the lack of it.</p>
- <p>For example, if this website is www.example.com, you would find the owner of the example.com domain at the following WHOIS server:</p>
- <p><a href="http://www.internic.net/whois.html">http://www.internic.net/whois.html</a></p>
- </div>
- <div class="col-sm-6">
- <h2>The CentOS Project</h2>
- <p>The CentOS Linux distribution is a stable, predictable, manageable and reproduceable platform derived from
- the sources of Red Hat Enterprise Linux (RHEL).<p>
- <p>Additionally to being a popular choice for web hosting, CentOS also provides a rich platform for open source communities to build upon. For more information
- please visit the <a href="http://www.centos.org/">CentOS website</a>.</p>
- </div>
- </div>
- </div>
- </div>
- </div>
- </body></html>
- [root@vm1 ~]#
- [root@vm1 ~]# vim /var/www/html/index.html
- [root@vm1 ~]# curl http://vm1.c.sixth-wave-179410.internal
- You are not supposed to see this.
- Please contact admin@example5.com
- [root@vm1 ~]# mkdir /srv/myapp
- [root@vm1 ~]# setenforce 0
- [root@vm1 ~]# vim /srv/myapp/myapp.py
- [root@vm1 ~]# chown apache:apache /srv/myapp/myapp.py
- \[root@vm1 ~]# chmod 750 /srv/myapp/myapp.py
- [root@vm1 ~]# sudo -u apache python /srv/myapp/myapp.py
- Traceback (most recent call last):
- File "/srv/myapp/myapp.py", line 1, in <module>
- from eventlet import wsgi
- ImportError: No module named eventlet
- [root@vm1 ~]# vim /srv/myapp/myapp.py
- [root@vm1 ~]# sudo -u apache python /srv/myapp/myapp.py
- [root@vm1 ~]# python /srv/myapp/myapp.py
- [root@vm1 ~]# vim /srv/myapp/myapp.py
- [root@vm1 ~]# python /srv/myapp/myapp.py
- [root@vm1 ~]# /srv/myapp/myapp.py
- /srv/myapp/myapp.py: line 1: syntax error near unexpected token `('
- /srv/myapp/myapp.py: line 1: `def application(environ, start_response):'
- [root@vm1 ~]# cd /etc/httpd/
- conf/ conf.d/ conf.modules.d/ logs/ modules/ run/
- [root@vm1 ~]# cd /etc/httpd/conf.d/
- [root@vm1 conf.d]# vim virtual1.conf
- [root@vm1 conf.d]# vim virtual1.conf
- [root@vm1 conf.d]# vim virtual1.conf
- [root@vm1 conf.d]# vim virtual1.conf
- [root@vm1 conf.d]# apachectl configtest
- Syntax OK
- [root@vm1 conf.d]# systemctl restart httpd
- [root@vm1 conf.d]# curl http://vm1.c.sixth-wave-179410.internal
- You are not supposed to see this.
- Please contact admin@example5.com
- [root@vm1 conf.d]# curl http://vm1.c.sixth-wave-179410.internal/myapp/
- Hello World![root@vm1 conf.d]# yum install setroubleshoot-server
- Loaded plugins: fastestmirror
- Loading mirror speeds from cached hostfile
- * base: mirror.steadfastnet.com
- * epel: mirror.steadfastnet.com
- * extras: ftpmirror.your.org
- * updates: mirrors.liquidweb.com
- Resolving Dependencies
- --> Running transaction check
- ---> Package setroubleshoot-server.x86_64 0:3.2.29-3.el7 will be installed
- --> Processing Dependency: systemd-python >= 206-1 for package: setroubleshoot-server-3.2.29-3.el7.x86_64
- --> Processing Dependency: setroubleshoot-plugins >= 3.0.62 for package: setroubleshoot-server-3.2.29-3.el7.x86_64
- --> Processing Dependency: pygobject2 for package: setroubleshoot-server-3.2.29-3.el7.x86_64
- --> Processing Dependency: libxml2-python for package: setroubleshoot-server-3.2.29-3.el7.x86_64
- --> Running transaction check
- ---> Package libxml2-python.x86_64 0:2.9.1-6.el7_2.3 will be installed
- ---> Package pygobject2.x86_64 0:2.28.6-11.el7 will be installed
- ---> Package setroubleshoot-plugins.noarch 0:3.0.66-2.1.el7 will be installed
- ---> Package systemd-python.x86_64 0:219-57.el7_5.1 will be installed
- --> Finished Dependency Resolution
- Dependencies Resolved
- =============================================================================================================================================================
- Package Arch Version Repository Size
- =============================================================================================================================================================
- Installing:
- setroubleshoot-server x86_64 3.2.29-3.el7 base 388 k
- Installing for dependencies:
- libxml2-python x86_64 2.9.1-6.el7_2.3 base 247 k
- pygobject2 x86_64 2.28.6-11.el7 base 226 k
- setroubleshoot-plugins noarch 3.0.66-2.1.el7 base 345 k
- systemd-python x86_64 219-57.el7_5.1 updates 128 k
- Transaction Summary
- =============================================================================================================================================================
- Install 1 Package (+4 Dependent packages)
- Total download size: 1.3 M
- Installed size: 6.3 M
- Is this ok [y/d/N]: y
- Downloading packages:
- (1/5): libxml2-python-2.9.1-6.el7_2.3.x86_64.rpm | 247 kB 00:00:00
- (2/5): pygobject2-2.28.6-11.el7.x86_64.rpm | 226 kB 00:00:00
- (3/5): setroubleshoot-plugins-3.0.66-2.1.el7.noarch.rpm | 345 kB 00:00:00
- (4/5): setroubleshoot-server-3.2.29-3.el7.x86_64.rpm | 388 kB 00:00:00
- (5/5): systemd-python-219-57.el7_5.1.x86_64.rpm | 128 kB 00:00:00
- -------------------------------------------------------------------------------------------------------------------------------------------------------------
- Total 2.7 MB/s | 1.3 MB 00:00:00
- Running transaction check
- Running transaction test
- Transaction test succeeded
- Running transaction
- Installing : systemd-python-219-57.el7_5.1.x86_64 1/5
- Installing : libxml2-python-2.9.1-6.el7_2.3.x86_64 2/5
- Installing : pygobject2-2.28.6-11.el7.x86_64 3/5
- Installing : setroubleshoot-server-3.2.29-3.el7.x86_64 4/5
- Installing : setroubleshoot-plugins-3.0.66-2.1.el7.noarch 5/5
- Verifying : setroubleshoot-plugins-3.0.66-2.1.el7.noarch 1/5
- Verifying : setroubleshoot-server-3.2.29-3.el7.x86_64 2/5
- Verifying : pygobject2-2.28.6-11.el7.x86_64 3/5
- Verifying : libxml2-python-2.9.1-6.el7_2.3.x86_64 4/5
- Verifying : systemd-python-219-57.el7_5.1.x86_64 5/5
- Installed:
- setroubleshoot-server.x86_64 0:3.2.29-3.el7
- Dependency Installed:
- libxml2-python.x86_64 0:2.9.1-6.el7_2.3 pygobject2.x86_64 0:2.28.6-11.el7 setroubleshoot-plugins.noarch 0:3.0.66-2.1.el7
- systemd-python.x86_64 0:219-57.el7_5.1
- Complete!
- [root@vm1 conf.d]# sealert -a /var/log/audit/audit.log
- 100% done
- found 2 alerts in /var/log/audit/audit.log
- --------------------------------------------------------------------------------
- SELinux is preventing /usr/sbin/httpd from getattr access on the file /srv/myapp/myapp.py.
- ***** Plugin catchall_labels (83.8 confidence) suggests *******************
- If you want to allow httpd to have getattr access on the myapp.py file
- Then you need to change the label on /srv/myapp/myapp.py
- Do
- # semanage fcontext -a -t FILE_TYPE '/srv/myapp/myapp.py'
- where FILE_TYPE is one of the following: NetworkManager_exec_t, NetworkManager_log_t, NetworkManager_tmp_t, abrt_dump_oops_exec_t, abrt_etc_t, abrt_exec_t, abrt_handle_event_exec_t, abrt_helper_exec_t, abrt_retrace_coredump_exec_t, abrt_retrace_spool_t, abrt_retrace_worker_exec_t, abrt_tmp_t, abrt_upload_watch_tmp_t, abrt_var_cache_t, abrt_var_log_t, abrt_var_run_t, accountsd_exec_t, acct_data_t, acct_exec_t, admin_crontab_tmp_t, admin_passwd_exec_t, afs_logfile_t, aide_exec_t, aide_log_t, alsa_exec_t, alsa_tmp_t, amanda_exec_t, amanda_log_t, amanda_recover_exec_t, amanda_tmp_t, amtu_exec_t, anacron_exec_t, anon_inodefs_t, antivirus_exec_t, antivirus_log_t, antivirus_tmp_t, apcupsd_cgi_content_t, apcupsd_cgi_htaccess_t, apcupsd_cgi_ra_content_t, apcupsd_cgi_rw_content_t, apcupsd_cgi_script_exec_t, apcupsd_log_t, apcupsd_tmp_t, apm_exec_t, apmd_log_t, apmd_tmp_t, arpwatch_tmp_t, asterisk_log_t, asterisk_tmp_t, audisp_exec_t, auditadm_sudo_tmp_t, auditctl_exec_t, auth_cache_t, authconfig_exec_t, automount_tmp_t, avahi_exec_t, awstats_content_t, awstats_htaccess_t, awstats_ra_content_t, awstats_rw_content_t, awstats_script_exec_t, awstats_tmp_t, bacula_admin_exec_t, bacula_log_t, bacula_tmp_t, bacula_unconfined_script_exec_t, bin_t, bitlbee_log_t, bitlbee_tmp_t, blueman_exec_t, bluetooth_helper_exec_t, bluetooth_helper_tmp_t, bluetooth_helper_tmpfs_t, bluetooth_tmp_t, boinc_log_t, boinc_project_tmp_t, boinc_tmp_t, boot_t, bootloader_exec_t, bootloader_tmp_t, brctl_exec_t, brltty_log_t, bugzilla_content_t, bugzilla_htaccess_t, bugzilla_ra_content_t, bugzilla_rw_content_t, bugzilla_script_exec_t, bugzilla_tmp_t, calamaris_exec_t, calamaris_log_t, calamaris_www_t, callweaver_log_t, canna_log_t, cardctl_exec_t, cardmgr_dev_t, ccs_tmp_t, ccs_var_lib_t, ccs_var_log_t, cdcc_exec_t, cdcc_tmp_t, cdrecord_exec_t, cert_t, certmaster_var_log_t, certmonger_unconfined_exec_t, certwatch_exec_t, cfengine_log_t, cgred_log_t, checkpc_exec_t, checkpc_log_t, checkpolicy_exec_t, chfn_exec_t, chkpwd_exec_t, chrome_sandbox_exec_t, chrome_sandbox_nacl_exec_t, chrome_sandbox_tmp_t, chronyc_exec_t, chronyd_var_log_t, cinder_api_tmp_t, cinder_backup_tmp_t, cinder_log_t, cinder_scheduler_tmp_t, cinder_volume_tmp_t, cloud_init_tmp_t, cloud_log_t, cluster_conf_t, cluster_tmp_t, cluster_var_lib_t, cluster_var_log_t, cluster_var_run_t, cobbler_etc_t, cobbler_tmp_t, cobbler_var_lib_t, cobbler_var_log_t, cockpit_tmp_t, collectd_content_t, collectd_htaccess_t, collectd_ra_content_t, collectd_rw_content_t, collectd_script_exec_t, collectd_script_tmp_t, colord_exec_t, colord_tmp_t, comsat_tmp_t, condor_log_t, condor_master_tmp_t, condor_schedd_tmp_t, condor_startd_tmp_t, conman_log_t, conman_tmp_t, conman_unconfined_script_exec_t, consolehelper_exec_t, consolekit_exec_t, consolekit_log_t, container_log_t, container_runtime_tmp_t, couchdb_log_t, couchdb_tmp_t, courier_exec_t, cpu_online_t, cpucontrol_exec_t, cpufreqselector_exec_t, cpuspeed_exec_t, crack_exec_t, crack_tmp_t, cron_log_t, crond_tmp_t, crontab_exec_t, crontab_tmp_t, ctdbd_log_t, ctdbd_tmp_t, cups_pdf_tmp_t, cupsd_config_exec_t, cupsd_log_t, cupsd_lpd_tmp_t, cupsd_tmp_t, cvs_content_t, cvs_data_t, cvs_exec_t, cvs_htaccess_t, cvs_ra_content_t, cvs_rw_content_t, cvs_script_exec_t, cvs_tmp_t, cyphesis_exec_t, cyphesis_log_t, cyphesis_tmp_t, cyrus_tmp_t, dbadm_sudo_tmp_t, dbskkd_tmp_t, dbusd_etc_t, dbusd_exec_t, dcc_client_exec_t, dcc_client_tmp_t, dcc_dbclean_exec_t, dcc_dbclean_tmp_t, dccd_tmp_t, dccifd_tmp_t, dccm_tmp_t, ddclient_log_t, ddclient_tmp_t, debuginfo_exec_t, deltacloudd_log_t, deltacloudd_tmp_t, denyhosts_var_log_t, depmod_exec_t, devicekit_disk_exec_t, devicekit_exec_t, devicekit_power_exec_t, devicekit_tmp_t, devicekit_var_log_t, dhcpc_exec_t, dhcpc_tmp_t, dhcpd_tmp_t, dirsrv_config_t, dirsrv_share_t, dirsrv_snmp_var_log_t, dirsrv_tmp_t, dirsrv_var_log_t, dirsrv_var_run_t, dirsrvadmin_config_t, dirsrvadmin_content_t, dirsrvadmin_htaccess_t, dirsrvadmin_ra_content_t, dirsrvadmin_rw_content_t, dirsrvadmin_script_exec_t, dirsrvadmin_tmp_t, dirsrvadmin_unconfined_script_exec_t, disk_munin_plugin_exec_t, disk_munin_plugin_tmp_t, dkim_milter_tmp_t, dlm_controld_var_log_t, dmesg_exec_t, dmidecode_exec_t, dnsmasq_var_log_t, dnssec_trigger_tmp_t, dovecot_auth_tmp_t, dovecot_deliver_tmp_t, dovecot_tmp_t, dovecot_var_log_t, drbd_tmp_t, dspam_content_t, dspam_htaccess_t, dspam_log_t, dspam_ra_content_t, dspam_rw_content_t, dspam_script_exec_t, etc_runtime_t, etc_t, evtchnd_var_log_t, exim_exec_t, exim_log_t, exim_tmp_t, fail2ban_client_exec_t, fail2ban_log_t, fail2ban_tmp_t, fail2ban_var_lib_t, faillog_t, fenced_tmp_t, fenced_var_log_t, fetchmail_exec_t, fetchmail_log_t, file_context_t, fingerd_log_t, firewalld_exec_t, firewalld_tmp_t, firewalld_var_log_t, firewallgui_exec_t, firewallgui_tmp_t, firstboot_exec_t, foghorn_var_log_t, fonts_cache_t, fonts_t, fprintd_exec_t, freqset_exec_t, fsadm_exec_t, fsadm_log_t, fsadm_tmp_t, fsdaemon_tmp_t, ftpd_tmp_t, ftpdctl_exec_t, ftpdctl_tmp_t, games_exec_t, games_tmp_t, games_tmpfs_t, ganesha_tmp_t, ganesha_var_log_t, gconf_tmp_t, gconfd_exec_t, gconfdefaultsm_exec_t, geoclue_exec_t, geoclue_tmp_t, getty_exec_t, getty_log_t, getty_tmp_t, gfs_controld_var_log_t, git_content_t, git_htaccess_t, git_ra_content_t, git_rw_content_t, git_script_exec_t, git_script_tmp_t, git_sys_content_t, gitd_exec_t, gitosis_exec_t, gitosis_var_lib_t, gkeyringd_exec_t, gkeyringd_tmp_t, glance_log_t, glance_registry_tmp_t, glance_tmp_t, glusterd_log_t, glusterd_tmp_t, gnomesystemmm_exec_t, gpg_agent_exec_t, gpg_agent_tmp_t, gpg_exec_t, gpg_helper_exec_t, gpg_pinentry_tmp_t, gpg_pinentry_tmpfs_t, gpm_tmp_t, gpsd_exec_t, groupadd_exec_t, groupd_var_log_t, gssd_tmp_t, haproxy_var_log_t, hostname_etc_t, hostname_exec_t, hsqldb_tmp_t, httpd_cache_t, httpd_config_t, httpd_exec_t, httpd_helper_exec_t, httpd_keytab_t, httpd_lock_t, httpd_log_t, httpd_modules_t, httpd_passwd_exec_t, httpd_php_exec_t, httpd_php_tmp_t, httpd_rotatelogs_exec_t, httpd_squirrelmail_t, httpd_suexec_exec_t, httpd_suexec_tmp_t, httpd_sys_content_t, httpd_sys_htaccess_t, httpd_sys_ra_content_t, httpd_sys_rw_content_t, httpd_sys_script_exec_t, httpd_tmp_t, httpd_tmpfs_t, httpd_unconfined_script_exec_t, httpd_user_htaccess_t, httpd_user_ra_content_t, httpd_user_rw_content_t, httpd_user_script_exec_t, httpd_var_lib_t, httpd_var_run_t, hugetlbfs_t, hwclock_exec_t, hwloc_dhwd_exec_t, iceauth_exec_t, icecast_exec_t, icecast_log_t, ifconfig_exec_t, inetd_child_tmp_t, inetd_log_t, inetd_tmp_t, init_tmp_t, initrc_tmp_t, initrc_var_log_t, innd_log_t, insmod_exec_t, install_exec_t, iotop_exec_t, ipa_cert_t, ipa_helper_exec_t, ipa_log_t, ipa_tmp_t, ipa_var_lib_t, ipa_var_run_t, ipsec_log_t, ipsec_mgmt_exec_t, ipsec_tmp_t, iptables_exec_t, iptables_tmp_t, irc_exec_t, irssi_exec_t, iscsi_log_t, iscsi_tmp_t, iso9660_t, iwhd_log_t, jetty_cache_t, jetty_log_t, jetty_var_lib_t, jetty_var_run_t, jockey_exec_t, jockey_var_log_t, journalctl_exec_t, kadmind_log_t, kadmind_tmp_t, kdump_exec_t, kdumpctl_tmp_t, kdumpgui_exec_t, kdumpgui_tmp_t, keepalived_unconfined_script_exec_t, keystone_cgi_content_t, keystone_cgi_htaccess_t, keystone_cgi_ra_content_t, keystone_cgi_rw_content_t, keystone_cgi_script_exec_t, keystone_log_t, keystone_tmp_t, kismet_exec_t, kismet_log_t, kismet_tmp_t, kismet_tmpfs_t, klogd_tmp_t, krb5_conf_t, krb5_host_rcache_t, krb5_keytab_t, krb5kdc_conf_t, krb5kdc_log_t, krb5kdc_tmp_t, ksmtuned_log_t, ktalkd_log_t, ktalkd_tmp_t, l2tpd_tmp_t, lastlog_t, ld_so_cache_t, ld_so_t, ldconfig_exec_t, ldconfig_tmp_t, lib_t, livecd_exec_t, livecd_tmp_t, load_policy_exec_t, loadkeys_exec_t, locale_t, locate_exec_t, lockdev_exec_t, login_exec_t, logrotate_mail_tmp_t, logrotate_tmp_t, logwatch_exec_t, logwatch_mail_tmp_t, logwatch_tmp_t, lpd_tmp_t, lpr_exec_t, lpr_tmp_t, lsassd_tmp_t, lsmd_plugin_exec_t, lsmd_plugin_tmp_t, lvm_exec_t, lvm_tmp_t, machineid_t, mail_munin_plugin_exec_t, mail_munin_plugin_tmp_t, mailman_archive_t, mailman_cgi_exec_t, mailman_cgi_tmp_t, mailman_data_t, mailman_log_t, mailman_mail_tmp_t, mailman_queue_tmp_t, man2html_content_t, man2html_htaccess_t, man2html_ra_content_t, man2html_rw_content_t, man2html_script_exec_t, man_cache_t, man_t, mandb_cache_t, mcelog_exec_t, mcelog_log_t, mdadm_log_t, mdadm_tmp_t, mediawiki_content_t, mediawiki_htaccess_t, mediawiki_ra_content_t, mediawiki_rw_content_t, mediawiki_script_exec_t, mediawiki_tmp_t, mencoder_exec_t, minidlna_log_t, mirrormanager_exec_t, mirrormanager_log_t, mirrormanager_var_lib_t, mirrormanager_var_run_t, mock_build_exec_t, mock_exec_t, mock_tmp_t, modemmanager_exec_t, mojomojo_content_t, mojomojo_htaccess_t, mojomojo_ra_content_t, mojomojo_rw_content_t, mojomojo_script_exec_t, mojomojo_tmp_t, mongod_log_t, mongod_tmp_t, motion_log_t, mount_ecryptfs_exec_t, mount_exec_t, mount_tmp_t, mozilla_exec_t, mozilla_plugin_config_exec_t, mozilla_plugin_exec_t, mozilla_plugin_tmp_t, mozilla_plugin_tmpfs_t, mozilla_tmp_t, mozilla_tmpfs_t, mpd_exec_t, mpd_log_t, mpd_tmp_t, mplayer_exec_t, mplayer_tmpfs_t, mrtg_exec_t, mrtg_log_t, mscan_tmp_t, munin_content_t, munin_etc_t, munin_htaccess_t, munin_log_t, munin_ra_content_t, munin_rw_content_t, munin_script_exec_t, munin_script_tmp_t, munin_tmp_t, mysqld_etc_t, mysqld_log_t, mysqld_tmp_t, mythtv_content_t, mythtv_htaccess_t, mythtv_ra_content_t, mythtv_rw_content_t, mythtv_script_exec_t, mythtv_var_log_t, nagios_admin_plugin_exec_t, nagios_checkdisk_plugin_exec_t, nagios_content_t, nagios_etc_t, nagios_eventhandler_plugin_exec_t, nagios_eventhandler_plugin_tmp_t, nagios_htaccess_t, nagios_log_t, nagios_mail_plugin_exec_t, nagios_openshift_plugin_exec_t, nagios_openshift_plugin_tmp_t, nagios_ra_content_t, nagios_rw_content_t, nagios_script_exec_t, nagios_services_plugin_exec_t, nagios_system_plugin_exec_t, nagios_system_plugin_tmp_t, nagios_tmp_t, nagios_unconfined_plugin_exec_t, nagios_var_lib_t, named_checkconf_exec_t, named_exec_t, named_log_t, named_tmp_t, namespace_init_exec_t, ncftool_exec_t, ndc_exec_t, net_conf_t, netlabel_mgmt_exec_t, netutils_exec_t, netutils_tmp_t, neutron_log_t, neutron_tmp_t, newrole_exec_t, nova_log_t, nova_tmp_t, nscd_log_t, nsd_log_t, nsd_tmp_t, ntop_tmp_t, ntpd_log_t, ntpd_tmp_t, ntpdate_exec_t, numad_var_log_t, nut_upsd_tmp_t, nut_upsdrvctl_tmp_t, nut_upsmon_tmp_t, nutups_cgi_content_t, nutups_cgi_htaccess_t, nutups_cgi_ra_content_t, nutups_cgi_rw_content_t, nutups_cgi_script_exec_t, nx_server_tmp_t, obex_exec_t, oddjob_mkhomedir_exec_t, opendnssec_tmp_t, openhpid_log_t, openshift_cgroup_read_exec_t, openshift_cgroup_read_tmp_t, openshift_content_t, openshift_cron_tmp_t, openshift_htaccess_t, openshift_initrc_tmp_t, openshift_log_t, openshift_net_read_exec_t, openshift_ra_content_t, openshift_rw_content_t, openshift_script_exec_t, openshift_tmp_t, openshift_var_lib_t, opensm_log_t, openvpn_status_t, openvpn_tmp_t, openvpn_var_log_t, openvswitch_log_t, openvswitch_tmp_t, openwsman_log_t, openwsman_tmp_t, oracleasm_tmp_t, osad_log_t, pads_exec_t, pam_console_exec_t, pam_timestamp_tmp_t, passenger_exec_t, passenger_log_t, passenger_tmp_t, passenger_var_lib_t, passenger_var_run_t, passwd_exec_t, passwd_file_t, pcp_log_t, pcp_tmp_t, pcscd_var_run_t, pegasus_openlmi_storage_tmp_t, pegasus_tmp_t, pinentry_exec_t, ping_exec_t, piranha_log_t, piranha_web_tmp_t, pkcs_slotd_log_t, pkcs_slotd_tmp_t, pki_ra_etc_rw_t, pki_ra_log_t, pki_ra_var_lib_t, pki_ra_var_run_t, pki_tomcat_cert_t, pki_tomcat_log_t, pki_tomcat_tmp_t, pki_tps_etc_rw_t, pki_tps_log_t, pki_tps_var_lib_t, pki_tps_var_run_t, plymouth_exec_t, plymouthd_var_log_t, podsleuth_exec_t, podsleuth_tmp_t, podsleuth_tmpfs_t, policykit_auth_exec_t, policykit_exec_t, policykit_grant_exec_t, policykit_resolve_exec_t, policykit_tmp_t, polipo_exec_t, polipo_log_t, portmap_helper_exec_t, portmap_tmp_t, postfix_bounce_tmp_t, postfix_cleanup_tmp_t, postfix_exec_t, postfix_local_tmp_t, postfix_map_exec_t, postfix_map_tmp_t, postfix_pickup_tmp_t, postfix_pipe_tmp_t, postfix_postdrop_exec_t, postfix_postdrop_t, postfix_postqueue_exec_t, postfix_qmgr_tmp_t, postfix_showq_exec_t, postfix_smtp_tmp_t, postfix_smtpd_tmp_t, postfix_virtual_tmp_t, postgresql_log_t, postgresql_tmp_t, pppd_exec_t, pppd_log_t, pppd_tmp_t, pptp_log_t, prelink_exec_t, prelink_log_t, prelink_tmp_t, prelude_lml_tmp_t, prelude_log_t, preupgrade_data_t, preupgrade_exec_t, prewikka_content_t, prewikka_htaccess_t, prewikka_ra_content_t, prewikka_rw_content_t, prewikka_script_exec_t, privoxy_log_t, proc_t, procmail_exec_t, procmail_log_t, procmail_tmp_t, prosody_log_t, prosody_tmp_t, psad_tmp_t, psad_var_log_t, ptchown_exec_t, public_content_rw_t, public_content_t, pulseaudio_exec_t, pulseaudio_tmpfs_t, puppet_log_t, puppet_tmp_t, puppet_var_lib_t, puppetca_exec_t, puppetmaster_tmp_t, pwauth_exec_t, pyicqt_log_t, qdiskd_var_log_t, qemu_exec_t, qmail_tcp_env_exec_t, qpidd_tmp_t, quota_exec_t, rabbitmq_var_log_t, racoon_tmp_t, radiusd_log_t, readahead_exec_t, realmd_exec_t, realmd_tmp_t, realmd_var_lib_t, redis_log_t, rhev_agentd_log_t, rhev_agentd_tmp_t, rhsmcertd_exec_t, rhsmcertd_log_t, rhsmcertd_tmp_t, ricci_modcluster_var_log_t, ricci_tmp_t, ricci_var_log_t, rkhunter_var_lib_t, rlogind_tmp_t, rpcbind_tmp_t, rpm_exec_t, rpm_log_t, rpm_script_tmp_t, rpm_tmp_t, rssh_chroot_helper_exec_t, rssh_exec_t, rsync_exec_t, rsync_log_t, rsync_tmp_t, rtas_errd_log_t, rtas_errd_tmp_t, rtkit_daemon_exec_t, run_init_exec_t, samba_etc_t, samba_log_t, samba_net_exec_t, samba_net_tmp_t, samba_var_t, sambagui_exec_t, sanlock_log_t, sbd_tmpfs_t, sblim_tmp_t, screen_exec_t, secadm_sudo_tmp_t, sectool_tmp_t, sectool_var_log_t, sectoolm_exec_t, security_t, selinux_munin_plugin_exec_t, selinux_munin_plugin_tmp_t, semanage_exec_t, semanage_tmp_t, sendmail_exec_t, sendmail_log_t, sendmail_tmp_t, sensord_log_t, services_munin_plugin_exec_t, services_munin_plugin_tmp_t, session_dbusd_tmp_t, setfiles_exec_t, setkey_exec_t, setroubleshoot_fixit_exec_t, setroubleshoot_var_log_t, setroubleshootd_exec_t, setsebool_exec_t, seunshare_exec_t, sge_job_exec_t, sge_shepherd_exec_t, sge_tmp_t, shell_exec_t, shorewall_log_t, shorewall_tmp_t, showmount_exec_t, slapd_cert_t, slapd_log_t, slapd_tmp_t, slpd_log_t, smbcontrol_exec_t, smbd_tmp_t, smokeping_cgi_content_t, smokeping_cgi_htaccess_t, smokeping_cgi_ra_content_t, smokeping_cgi_rw_content_t, smokeping_cgi_script_exec_t, smokeping_var_lib_t, smokeping_var_run_t, smoltclient_exec_t, smoltclient_tmp_t, smsd_log_t, smsd_tmp_t, snapperd_exec_t, snapperd_log_t, snmpd_log_t, snort_log_t, snort_tmp_t, sosreport_exec_t, sosreport_tmp_t, soundd_tmp_t, spamc_exec_t, spamc_tmp_t, spamd_log_t, spamd_tmp_t, spamd_update_exec_t, speech-dispatcher_exec_t, speech-dispatcher_log_t, speech-dispatcher_tmp_t, squid_content_t, squid_cron_exec_t, squid_htaccess_t, squid_log_t, squid_ra_content_t, squid_rw_content_t, squid_script_exec_t, squid_tmp_t, squirrelmail_spool_t, src_t, ssh_agent_exec_t, ssh_agent_tmp_t, ssh_exec_t, ssh_keygen_exec_t, ssh_keygen_tmp_t, ssh_keysign_exec_t, ssh_tmpfs_t, sssd_public_t, sssd_selinux_manager_exec_t, sssd_var_lib_t, sssd_var_log_t, staff_sudo_tmp_t, stapserver_log_t, stapserver_tmp_t, stunnel_log_t, stunnel_tmp_t, su_exec_t, sudo_exec_t, sulogin_exec_t, svc_multilog_exec_t, svc_run_exec_t, svc_start_exec_t, svirt_tmp_t, svnserve_log_t, svnserve_tmp_t, swat_tmp_t, swift_tmp_t, sysadm_passwd_tmp_t, sysadm_sudo_tmp_t, sysfs_t, syslogd_tmp_t, sysstat_exec_t, sysstat_log_t, system_conf_t, system_cronjob_tmp_t, system_db_t, system_dbusd_tmp_t, system_dbusd_var_lib_t, system_mail_tmp_t, system_munin_plugin_exec_t, system_munin_plugin_tmp_t, systemd_passwd_var_run_t, targetd_tmp_t, tcpd_tmp_t, telepathy_gabble_exec_t, telepathy_gabble_tmp_t, telepathy_idle_exec_t, telepathy_idle_tmp_t, telepathy_logger_exec_t, telepathy_logger_tmp_t, telepathy_mission_control_exec_t, telepathy_mission_control_tmp_t, telepathy_msn_exec_t, telepathy_msn_tmp_t, telepathy_salut_exec_t, telepathy_salut_tmp_t, telepathy_sofiasip_exec_t, telepathy_sofiasip_tmp_t, telepathy_stream_engine_exec_t, telepathy_stream_engine_tmp_t, telepathy_sunshine_exec_t, telepathy_sunshine_tmp_t, telnetd_tmp_t, tetex_data_t, textrel_shlib_t, tgtd_tmp_t, thin_aeolus_configserver_log_t, thin_log_t, thumb_exec_t, thumb_tmp_t, tmp_t, tmpreaper_exec_t, tomcat_log_t, tomcat_tmp_t, tor_var_log_t, traceroute_exec_t, tuned_log_t, tuned_tmp_t, tvtime_exec_t, tvtime_tmp_t, tvtime_tmpfs_t, udev_tmp_t, udev_var_run_t, ulogd_var_log_t, uml_exec_t, uml_tmp_t, uml_tmpfs_t, unconfined_exec_t, unconfined_munin_plugin_exec_t, unconfined_munin_plugin_tmp_t, update_modules_exec_t, update_modules_tmp_t, updfstab_exec_t, usbmodules_exec_t, usbmuxd_exec_t, user_cron_spool_t, user_fonts_t, user_home_t, user_mail_tmp_t, user_tmp_t, useradd_exec_t, userhelper_exec_t, usernetctl_exec_t, usr_t, utempter_exec_t, uucpd_log_t, uucpd_tmp_t, uux_exec_t, var_lib_t, var_log_t, var_spool_t, varnishd_tmp_t, varnishlog_log_t, vdagent_log_t, virsh_exec_t, virt_log_t, virt_qemu_ga_log_t, virt_qemu_ga_tmp_t, virt_qemu_ga_unconfined_exec_t, virt_tmp_t, virtd_lxc_exec_t, vlock_exec_t, vmtools_helper_exec_t, vmtools_tmp_t, vmware_exec_t, vmware_host_tmp_t, vmware_log_t, vmware_tmp_t, vmware_tmpfs_t, vnstat_exec_t, vpnc_exec_t, vpnc_tmp_t, w3c_validator_content_t, w3c_validator_htaccess_t, w3c_validator_ra_content_t, w3c_validator_rw_content_t, w3c_validator_script_exec_t, w3c_validator_tmp_t, watchdog_log_t, watchdog_unconfined_exec_t, webadm_tmp_t, webalizer_content_t, webalizer_exec_t, webalizer_htaccess_t, webalizer_ra_content_t, webalizer_rw_content_t, webalizer_script_exec_t, webalizer_tmp_t, winbind_log_t, wine_exec_t, wireshark_exec_t, wireshark_tmp_t, wireshark_tmpfs_t, wpa_cli_exec_t, wtmp_t, xauth_exec_t, xauth_tmp_t, xdm_exec_t, xdm_log_t, xdm_unconfined_exec_t, xend_tmp_t, xend_var_log_t, xenstored_tmp_t, xenstored_var_log_t, xferlog_t, xserver_exec_t, xserver_log_t, xserver_tmpfs_t, ypbind_tmp_t, ypserv_tmp_t, zabbix_log_t, zabbix_script_exec_t, zabbix_tmp_t, zarafa_deliver_log_t, zarafa_deliver_tmp_t, zarafa_gateway_log_t, zarafa_ical_log_t, zarafa_indexer_log_t, zarafa_indexer_tmp_t, zarafa_monitor_log_t, zarafa_server_log_t, zarafa_server_tmp_t, zarafa_spooler_log_t, zarafa_var_lib_t, zebra_log_t, zebra_tmp_t, zoneminder_content_t, zoneminder_exec_t, zoneminder_htaccess_t, zoneminder_log_t, zoneminder_ra_content_t, zoneminder_rw_content_t, zoneminder_script_exec_t, zoneminder_var_lib_t, zos_remote_exec_t.
- Then execute:
- restorecon -v '/srv/myapp/myapp.py'
- ***** Plugin catchall (17.1 confidence) suggests **************************
- If you believe that httpd should be allowed getattr access on the myapp.py file by default.
- Then you should report this as a bug.
- You can generate a local policy module to allow this access.
- Do
- allow this access for now by executing:
- # ausearch -c 'httpd' --raw | audit2allow -M my-httpd
- # semodule -i my-httpd.pp
- Additional Information:
- Source Context system_u:system_r:httpd_t:s0
- Target Context unconfined_u:object_r:var_t:s0
- Target Objects /srv/myapp/myapp.py [ file ]
- Source httpd
- Source Path /usr/sbin/httpd
- Port <Unknown>
- Host <Unknown>
- Source RPM Packages httpd-2.4.6-80.el7.centos.1.x86_64
- Target RPM Packages
- Policy RPM selinux-policy-3.13.1-192.el7_5.6.noarch
- Selinux Enabled True
- Policy Type targeted
- Enforcing Mode Permissive
- Host Name vm1
- Platform Linux vm1 3.10.0-862.11.6.el7.x86_64 #1 SMP Tue
- Aug 14 21:49:04 UTC 2018 x86_64 x86_64
- Alert Count 1
- First Seen 2018-09-10 08:09:45 UTC
- Last Seen 2018-09-10 08:09:45 UTC
- Local ID e3e4a55c-db1b-43d7-a369-ee788ac5fcdf
- Raw Audit Messages
- type=AVC msg=audit(1536566985.960:291): avc: denied { getattr } for pid=1524 comm="httpd" path="/srv/myapp/myapp.py" dev="sda1" ino=25292922 scontext=system_u:system_r:httpd_t:s0 tcontext=unconfined_u:object_r:var_t:s0 tclass=file
- type=SYSCALL msg=audit(1536566985.960:291): arch=x86_64 syscall=stat success=yes exit=0 a0=557e0ed7fef8 a1=7ffc55ea7880 a2=7ffc55ea7880 a3=7f66c38c4712 items=0 ppid=1521 pid=1524 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 tty=(none) ses=4294967295 comm=httpd exe=/usr/sbin/httpd subj=system_u:system_r:httpd_t:s0 key=(null)
- Hash: httpd,httpd_t,var_t,file,getattr
- --------------------------------------------------------------------------------
- SELinux is preventing /usr/sbin/httpd from read access on the file myapp.py.
- ***** Plugin catchall_labels (83.8 confidence) suggests *******************
- If you want to allow httpd to have read access on the myapp.py file
- Then you need to change the label on myapp.py
- Do
- # semanage fcontext -a -t FILE_TYPE 'myapp.py'
- where FILE_TYPE is one of the following: NetworkManager_exec_t, NetworkManager_tmp_t, abrt_dump_oops_exec_t, abrt_etc_t, abrt_exec_t, abrt_handle_event_exec_t, abrt_helper_exec_t, abrt_retrace_coredump_exec_t, abrt_retrace_spool_t, abrt_retrace_worker_exec_t, abrt_tmp_t, abrt_upload_watch_tmp_t, abrt_var_cache_t, abrt_var_run_t, accountsd_exec_t, acct_exec_t, admin_crontab_tmp_t, admin_passwd_exec_t, afs_cache_t, aide_exec_t, alsa_exec_t, alsa_tmp_t, amanda_exec_t, amanda_recover_exec_t, amanda_tmp_t, amtu_exec_t, anacron_exec_t, anon_inodefs_t, antivirus_exec_t, antivirus_tmp_t, apcupsd_cgi_content_t, apcupsd_cgi_htaccess_t, apcupsd_cgi_ra_content_t, apcupsd_cgi_rw_content_t, apcupsd_cgi_script_exec_t, apcupsd_tmp_t, apm_exec_t, apmd_tmp_t, arpwatch_tmp_t, asterisk_tmp_t, audisp_exec_t, auditadm_sudo_tmp_t, auditctl_exec_t, authconfig_exec_t, automount_tmp_t, avahi_exec_t, awstats_content_t, awstats_htaccess_t, awstats_ra_content_t, awstats_rw_content_t, awstats_script_exec_t, awstats_tmp_t, bacula_admin_exec_t, bacula_tmp_t, bacula_unconfined_script_exec_t, bin_t, bitlbee_tmp_t, blueman_exec_t, bluetooth_helper_exec_t, bluetooth_helper_tmp_t, bluetooth_helper_tmpfs_t, bluetooth_tmp_t, boinc_project_tmp_t, boinc_tmp_t, boot_t, bootloader_exec_t, bootloader_tmp_t, brctl_exec_t, bugzilla_content_t, bugzilla_htaccess_t, bugzilla_ra_content_t, bugzilla_rw_content_t, bugzilla_script_exec_t, bugzilla_tmp_t, calamaris_exec_t, calamaris_www_t, cardctl_exec_t, cardmgr_dev_t, ccs_tmp_t, cdcc_exec_t, cdcc_tmp_t, cdrecord_exec_t, cert_t, certmonger_unconfined_exec_t, certwatch_exec_t, checkpc_exec_t, checkpolicy_exec_t, chfn_exec_t, chkpwd_exec_t, chrome_sandbox_exec_t, chrome_sandbox_nacl_exec_t, chrome_sandbox_tmp_t, chronyc_exec_t, cinder_api_tmp_t, cinder_backup_tmp_t, cinder_scheduler_tmp_t, cinder_volume_tmp_t, cloud_init_tmp_t, cluster_conf_t, cluster_tmp_t, cluster_var_lib_t, cluster_var_run_t, cobbler_etc_t, cobbler_tmp_t, cobbler_var_lib_t, cockpit_tmp_t, collectd_content_t, collectd_htaccess_t, collectd_ra_content_t, collectd_rw_content_t, collectd_script_exec_t, collectd_script_tmp_t, colord_exec_t, colord_tmp_t, comsat_tmp_t, condor_master_tmp_t, condor_schedd_tmp_t, condor_startd_tmp_t, conman_tmp_t, conman_unconfined_script_exec_t, consolehelper_exec_t, consolekit_exec_t, container_runtime_tmp_t, couchdb_tmp_t, courier_exec_t, cpu_online_t, cpucontrol_exec_t, cpufreqselector_exec_t, cpuspeed_exec_t, crack_exec_t, crack_tmp_t, crond_tmp_t, crontab_exec_t, crontab_tmp_t, ctdbd_tmp_t, cups_pdf_tmp_t, cupsd_config_exec_t, cupsd_lpd_tmp_t, cupsd_tmp_t, cvs_content_t, cvs_data_t, cvs_exec_t, cvs_htaccess_t, cvs_ra_content_t, cvs_rw_content_t, cvs_script_exec_t, cvs_tmp_t, cyphesis_exec_t, cyphesis_tmp_t, cyrus_tmp_t, dbadm_sudo_tmp_t, dbskkd_tmp_t, dbusd_etc_t, dbusd_exec_t, dcc_client_exec_t, dcc_client_tmp_t, dcc_dbclean_exec_t, dcc_dbclean_tmp_t, dccd_tmp_t, dccifd_tmp_t, dccm_tmp_t, ddclient_tmp_t, debuginfo_exec_t, deltacloudd_tmp_t, depmod_exec_t, devicekit_disk_exec_t, devicekit_exec_t, devicekit_power_exec_t, devicekit_tmp_t, dhcpc_exec_t, dhcpc_tmp_t, dhcpd_tmp_t, dirsrv_config_t, dirsrv_share_t, dirsrv_tmp_t, dirsrv_var_log_t, dirsrv_var_run_t, dirsrvadmin_config_t, dirsrvadmin_content_t, dirsrvadmin_htaccess_t, dirsrvadmin_ra_content_t, dirsrvadmin_rw_content_t, dirsrvadmin_script_exec_t, dirsrvadmin_tmp_t, dirsrvadmin_unconfined_script_exec_t, disk_munin_plugin_exec_t, disk_munin_plugin_tmp_t, dkim_milter_tmp_t, dmesg_exec_t, dmidecode_exec_t, dnssec_trigger_tmp_t, dovecot_auth_tmp_t, dovecot_deliver_tmp_t, dovecot_tmp_t, drbd_tmp_t, dspam_content_t, dspam_htaccess_t, dspam_ra_content_t, dspam_rw_content_t, dspam_script_exec_t, etc_runtime_t, etc_t, exim_exec_t, exim_tmp_t, fail2ban_client_exec_t, fail2ban_tmp_t, fail2ban_var_lib_t, fenced_tmp_t, fetchmail_exec_t, file_context_t, firewalld_exec_t, firewalld_tmp_t, firewallgui_exec_t, firewallgui_tmp_t, firstboot_exec_t, fonts_cache_t, fonts_t, fprintd_exec_t, freqset_exec_t, fsadm_exec_t, fsadm_tmp_t, fsdaemon_tmp_t, ftpd_tmp_t, ftpdctl_exec_t, ftpdctl_tmp_t, games_exec_t, games_tmp_t, games_tmpfs_t, ganesha_tmp_t, gconf_tmp_t, gconfd_exec_t, gconfdefaultsm_exec_t, geoclue_exec_t, geoclue_tmp_t, getty_exec_t, getty_tmp_t, git_content_t, git_htaccess_t, git_ra_content_t, git_rw_content_t, git_script_exec_t, git_script_tmp_t, git_sys_content_t, gitd_exec_t, gitosis_exec_t, gitosis_var_lib_t, gkeyringd_exec_t, gkeyringd_tmp_t, glance_registry_tmp_t, glance_tmp_t, glusterd_tmp_t, gnomesystemmm_exec_t, gpg_agent_exec_t, gpg_agent_tmp_t, gpg_exec_t, gpg_helper_exec_t, gpg_pinentry_tmp_t, gpg_pinentry_tmpfs_t, gpm_tmp_t, gpsd_exec_t, groupadd_exec_t, gssd_tmp_t, hostname_etc_t, hostname_exec_t, hsqldb_tmp_t, httpd_cache_t, httpd_config_t, httpd_exec_t, httpd_helper_exec_t, httpd_keytab_t, httpd_lock_t, httpd_log_t, httpd_modules_t, httpd_passwd_exec_t, httpd_php_exec_t, httpd_php_tmp_t, httpd_rotatelogs_exec_t, httpd_squirrelmail_t, httpd_suexec_exec_t, httpd_suexec_tmp_t, httpd_sys_content_t, httpd_sys_htaccess_t, httpd_sys_ra_content_t, httpd_sys_rw_content_t, httpd_sys_script_exec_t, httpd_tmp_t, httpd_tmpfs_t, httpd_unconfined_script_exec_t, httpd_user_htaccess_t, httpd_user_ra_content_t, httpd_user_rw_content_t, httpd_user_script_exec_t, httpd_var_lib_t, httpd_var_run_t, hugetlbfs_t, hwclock_exec_t, hwloc_dhwd_exec_t, iceauth_exec_t, icecast_exec_t, ifconfig_exec_t, inetd_child_tmp_t, inetd_tmp_t, init_tmp_t, initrc_tmp_t, insmod_exec_t, install_exec_t, iotop_exec_t, ipa_cert_t, ipa_helper_exec_t, ipa_tmp_t, ipa_var_lib_t, ipa_var_run_t, ipsec_mgmt_exec_t, ipsec_tmp_t, iptables_exec_t, iptables_tmp_t, irc_exec_t, irssi_exec_t, iscsi_tmp_t, iso9660_t, jetty_cache_t, jetty_log_t, jetty_var_lib_t, jetty_var_run_t, jockey_exec_t, journalctl_exec_t, kadmind_tmp_t, kdump_exec_t, kdumpctl_tmp_t, kdumpgui_exec_t, kdumpgui_tmp_t, keepalived_unconfined_script_exec_t, keystone_cgi_content_t, keystone_cgi_htaccess_t, keystone_cgi_ra_content_t, keystone_cgi_rw_content_t, keystone_cgi_script_exec_t, keystone_tmp_t, kismet_exec_t, kismet_tmp_t, kismet_tmpfs_t, klogd_tmp_t, krb5_conf_t, krb5_host_rcache_t, krb5_keytab_t, krb5kdc_conf_t, krb5kdc_tmp_t, ktalkd_tmp_t, l2tpd_tmp_t, ld_so_cache_t, ld_so_t, ldconfig_exec_t, ldconfig_tmp_t, lib_t, livecd_exec_t, livecd_tmp_t, load_policy_exec_t, loadkeys_exec_t, locale_t, locate_exec_t, lockdev_exec_t, login_exec_t, logrotate_mail_tmp_t, logrotate_tmp_t, logwatch_exec_t, logwatch_mail_tmp_t, logwatch_tmp_t, lpd_tmp_t, lpr_exec_t, lpr_tmp_t, lsassd_tmp_t, lsmd_plugin_exec_t, lsmd_plugin_tmp_t, lvm_exec_t, lvm_tmp_t, machineid_t, mail_munin_plugin_exec_t, mail_munin_plugin_tmp_t, mailman_archive_t, mailman_cgi_exec_t, mailman_cgi_tmp_t, mailman_data_t, mailman_mail_tmp_t, mailman_queue_tmp_t, man2html_content_t, man2html_htaccess_t, man2html_ra_content_t, man2html_rw_content_t, man2html_script_exec_t, man_cache_t, man_t, mandb_cache_t, mcelog_exec_t, mdadm_tmp_t, mediawiki_content_t, mediawiki_htaccess_t, mediawiki_ra_content_t, mediawiki_rw_content_t, mediawiki_script_exec_t, mediawiki_tmp_t, mencoder_exec_t, mirrormanager_exec_t, mirrormanager_log_t, mirrormanager_var_lib_t, mirrormanager_var_run_t, mock_build_exec_t, mock_exec_t, mock_tmp_t, modemmanager_exec_t, mojomojo_content_t, mojomojo_htaccess_t, mojomojo_ra_content_t, mojomojo_rw_content_t, mojomojo_script_exec_t, mojomojo_tmp_t, mongod_tmp_t, mount_ecryptfs_exec_t, mount_exec_t, mount_tmp_t, mozilla_exec_t, mozilla_plugin_config_exec_t, mozilla_plugin_exec_t, mozilla_plugin_tmp_t, mozilla_plugin_tmpfs_t, mozilla_tmp_t, mozilla_tmpfs_t, mpd_exec_t, mpd_tmp_t, mplayer_exec_t, mplayer_tmpfs_t, mrtg_exec_t, mscan_tmp_t, munin_content_t, munin_etc_t, munin_htaccess_t, munin_ra_content_t, munin_rw_content_t, munin_script_exec_t, munin_script_tmp_t, munin_tmp_t, mysqld_etc_t, mysqld_tmp_t, mythtv_content_t, mythtv_htaccess_t, mythtv_ra_content_t, mythtv_rw_content_t, mythtv_script_exec_t, nagios_admin_plugin_exec_t, nagios_checkdisk_plugin_exec_t, nagios_content_t, nagios_etc_t, nagios_eventhandler_plugin_exec_t, nagios_eventhandler_plugin_tmp_t, nagios_htaccess_t, nagios_log_t, nagios_mail_plugin_exec_t, nagios_openshift_plugin_exec_t, nagios_openshift_plugin_tmp_t, nagios_ra_content_t, nagios_rw_content_t, nagios_script_exec_t, nagios_services_plugin_exec_t, nagios_system_plugin_exec_t, nagios_system_plugin_tmp_t, nagios_tmp_t, nagios_unconfined_plugin_exec_t, nagios_var_lib_t, named_checkconf_exec_t, named_exec_t, named_tmp_t, namespace_init_exec_t, ncftool_exec_t, ndc_exec_t, net_conf_t, netlabel_mgmt_exec_t, netutils_exec_t, netutils_tmp_t, neutron_tmp_t, newrole_exec_t, nova_tmp_t, nsd_tmp_t, ntop_tmp_t, ntpd_tmp_t, ntpdate_exec_t, nut_upsd_tmp_t, nut_upsdrvctl_tmp_t, nut_upsmon_tmp_t, nutups_cgi_content_t, nutups_cgi_htaccess_t, nutups_cgi_ra_content_t, nutups_cgi_rw_content_t, nutups_cgi_script_exec_t, nx_server_tmp_t, obex_exec_t, oddjob_mkhomedir_exec_t, opendnssec_tmp_t, openshift_cgroup_read_exec_t, openshift_cgroup_read_tmp_t, openshift_content_t, openshift_cron_tmp_t, openshift_htaccess_t, openshift_initrc_tmp_t, openshift_net_read_exec_t, openshift_ra_content_t, openshift_rw_content_t, openshift_script_exec_t, openshift_tmp_t, openvpn_tmp_t, openvswitch_tmp_t, openwsman_tmp_t, oracleasm_tmp_t, pads_exec_t, pam_console_exec_t, pam_timestamp_tmp_t, passenger_exec_t, passenger_tmp_t, passenger_var_lib_t, passenger_var_run_t, passwd_exec_t, passwd_file_t, pcp_tmp_t, pcscd_var_run_t, pegasus_openlmi_storage_tmp_t, pegasus_tmp_t, pinentry_exec_t, ping_exec_t, piranha_web_tmp_t, pkcs_slotd_tmp_t, pki_ra_etc_rw_t, pki_ra_log_t, pki_ra_var_lib_t, pki_ra_var_run_t, pki_tomcat_cert_t, pki_tomcat_tmp_t, pki_tps_etc_rw_t, pki_tps_log_t, pki_tps_var_lib_t, pki_tps_var_run_t, plymouth_exec_t, podsleuth_exec_t, podsleuth_tmp_t, podsleuth_tmpfs_t, policykit_auth_exec_t, policykit_exec_t, policykit_grant_exec_t, policykit_resolve_exec_t, policykit_tmp_t, polipo_exec_t, portmap_helper_exec_t, portmap_tmp_t, postfix_bounce_tmp_t, postfix_cleanup_tmp_t, postfix_exec_t, postfix_local_tmp_t, postfix_map_exec_t, postfix_map_tmp_t, postfix_pickup_tmp_t, postfix_pipe_tmp_t, postfix_postdrop_exec_t, postfix_postdrop_t, postfix_postqueue_exec_t, postfix_qmgr_tmp_t, postfix_showq_exec_t, postfix_smtp_tmp_t, postfix_smtpd_tmp_t, postfix_virtual_tmp_t, postgresql_tmp_t, pppd_exec_t, pppd_tmp_t, prelink_exec_t, prelink_tmp_t, prelude_lml_tmp_t, preupgrade_data_t, preupgrade_exec_t, prewikka_content_t, prewikka_htaccess_t, prewikka_ra_content_t, prewikka_rw_content_t, prewikka_script_exec_t, proc_t, procmail_exec_t, procmail_tmp_t, prosody_tmp_t, psad_tmp_t, ptchown_exec_t, public_content_rw_t, public_content_t, pulseaudio_exec_t, pulseaudio_tmpfs_t, puppet_tmp_t, puppet_var_lib_t, puppetca_exec_t, puppetmaster_tmp_t, pwauth_exec_t, qemu_exec_t, qmail_tcp_env_exec_t, qpidd_tmp_t, quota_exec_t, racoon_tmp_t, readahead_exec_t, realmd_exec_t, realmd_tmp_t, realmd_var_lib_t, rhev_agentd_tmp_t, rhsmcertd_exec_t, rhsmcertd_tmp_t, ricci_tmp_t, rlogind_tmp_t, rpcbind_tmp_t, rpm_exec_t, rpm_script_tmp_t, rpm_tmp_t, rssh_chroot_helper_exec_t, rssh_exec_t, rsync_exec_t, rsync_tmp_t, rtas_errd_tmp_t, rtkit_daemon_exec_t, run_init_exec_t, samba_etc_t, samba_net_exec_t, samba_net_tmp_t, samba_var_t, sambagui_exec_t, sbd_tmpfs_t, sblim_tmp_t, screen_exec_t, secadm_sudo_tmp_t, sectool_tmp_t, sectoolm_exec_t, security_t, selinux_munin_plugin_exec_t, selinux_munin_plugin_tmp_t, semanage_exec_t, semanage_tmp_t, sendmail_exec_t, sendmail_tmp_t, services_munin_plugin_exec_t, services_munin_plugin_tmp_t, session_dbusd_tmp_t, setfiles_exec_t, setkey_exec_t, setroubleshoot_fixit_exec_t, setroubleshootd_exec_t, setsebool_exec_t, seunshare_exec_t, sge_job_exec_t, sge_shepherd_exec_t, sge_tmp_t, shell_exec_t, shorewall_tmp_t, showmount_exec_t, slapd_cert_t, slapd_tmp_t, smbcontrol_exec_t, smbd_tmp_t, smokeping_cgi_content_t, smokeping_cgi_htaccess_t, smokeping_cgi_ra_content_t, smokeping_cgi_rw_content_t, smokeping_cgi_script_exec_t, smokeping_var_lib_t, smokeping_var_run_t, smoltclient_exec_t, smoltclient_tmp_t, smsd_tmp_t, snapperd_exec_t, snort_tmp_t, sosreport_exec_t, sosreport_tmp_t, soundd_tmp_t, spamc_exec_t, spamc_tmp_t, spamd_tmp_t, spamd_update_exec_t, speech-dispatcher_exec_t, speech-dispatcher_tmp_t, squid_content_t, squid_cron_exec_t, squid_htaccess_t, squid_ra_content_t, squid_rw_content_t, squid_script_exec_t, squid_tmp_t, squirrelmail_spool_t, src_t, ssh_agent_exec_t, ssh_agent_tmp_t, ssh_exec_t, ssh_keygen_exec_t, ssh_keygen_tmp_t, ssh_keysign_exec_t, ssh_tmpfs_t, sssd_public_t, sssd_selinux_manager_exec_t, sssd_var_lib_t, staff_sudo_tmp_t, stapserver_tmp_t, stunnel_tmp_t, su_exec_t, sudo_exec_t, sulogin_exec_t, svc_multilog_exec_t, svc_run_exec_t, svc_start_exec_t, svirt_tmp_t, svnserve_tmp_t, swat_tmp_t, swift_tmp_t, sysadm_passwd_tmp_t, sysadm_sudo_tmp_t, sysfs_t, syslogd_tmp_t, sysstat_exec_t, system_conf_t, system_cronjob_tmp_t, system_db_t, system_dbusd_tmp_t, system_dbusd_var_lib_t, system_mail_tmp_t, system_munin_plugin_exec_t, system_munin_plugin_tmp_t, systemd_passwd_var_run_t, targetd_tmp_t, tcpd_tmp_t, telepathy_gabble_exec_t, telepathy_gabble_tmp_t, telepathy_idle_exec_t, telepathy_idle_tmp_t, telepathy_logger_exec_t, telepathy_logger_tmp_t, telepathy_mission_control_exec_t, telepathy_mission_control_tmp_t, telepathy_msn_exec_t, telepathy_msn_tmp_t, telepathy_salut_exec_t, telepathy_salut_tmp_t, telepathy_sofiasip_exec_t, telepathy_sofiasip_tmp_t, telepathy_stream_engine_exec_t, telepathy_stream_engine_tmp_t, telepathy_sunshine_exec_t, telepathy_sunshine_tmp_t, telnetd_tmp_t, tetex_data_t, textrel_shlib_t, tgtd_tmp_t, thumb_exec_t, thumb_tmp_t, tmp_t, tmpreaper_exec_t, tomcat_tmp_t, traceroute_exec_t, tuned_tmp_t, tvtime_exec_t, tvtime_tmp_t, tvtime_tmpfs_t, udev_tmp_t, udev_var_run_t, uml_exec_t, uml_tmp_t, uml_tmpfs_t, unconfined_exec_t, unconfined_munin_plugin_exec_t, unconfined_munin_plugin_tmp_t, update_modules_exec_t, update_modules_tmp_t, updfstab_exec_t, usbmodules_exec_t, usbmuxd_exec_t, user_cron_spool_t, user_fonts_t, user_mail_tmp_t, user_tmp_t, useradd_exec_t, userhelper_exec_t, usernetctl_exec_t, usr_t, utempter_exec_t, uucpd_tmp_t, uux_exec_t, var_lib_t, var_spool_t, varnishd_tmp_t, virsh_exec_t, virt_qemu_ga_tmp_t, virt_qemu_ga_unconfined_exec_t, virt_tmp_t, virtd_lxc_exec_t, vlock_exec_t, vmtools_helper_exec_t, vmtools_tmp_t, vmware_exec_t, vmware_host_tmp_t, vmware_tmp_t, vmware_tmpfs_t, vnstat_exec_t, vpnc_exec_t, vpnc_tmp_t, w3c_validator_content_t, w3c_validator_htaccess_t, w3c_validator_ra_content_t, w3c_validator_rw_content_t, w3c_validator_script_exec_t, w3c_validator_tmp_t, watchdog_unconfined_exec_t, webadm_tmp_t, webalizer_content_t, webalizer_exec_t, webalizer_htaccess_t, webalizer_ra_content_t, webalizer_rw_content_t, webalizer_script_exec_t, webalizer_tmp_t, wine_exec_t, wireshark_exec_t, wireshark_tmp_t, wireshark_tmpfs_t, wpa_cli_exec_t, xauth_exec_t, xauth_tmp_t, xdm_exec_t, xdm_unconfined_exec_t, xend_tmp_t, xenstored_tmp_t, xserver_exec_t, xserver_tmpfs_t, ypbind_tmp_t, ypserv_tmp_t, zabbix_script_exec_t, zabbix_tmp_t, zarafa_deliver_tmp_t, zarafa_indexer_tmp_t, zarafa_server_tmp_t, zarafa_var_lib_t, zebra_tmp_t, zoneminder_content_t, zoneminder_exec_t, zoneminder_htaccess_t, zoneminder_ra_content_t, zoneminder_rw_content_t, zoneminder_script_exec_t, zoneminder_var_lib_t, zos_remote_exec_t.
- Then execute:
- restorecon -v 'myapp.py'
- ***** Plugin catchall (17.1 confidence) suggests **************************
- If you believe that httpd should be allowed read access on the myapp.py file by default.
- Then you should report this as a bug.
- You can generate a local policy module to allow this access.
- Do
- allow this access for now by executing:
- # ausearch -c 'httpd' --raw | audit2allow -M my-httpd
- # semodule -i my-httpd.pp
- Additional Information:
- Source Context system_u:system_r:httpd_t:s0
- Target Context unconfined_u:object_r:var_t:s0
- Target Objects myapp.py [ file ]
- Source httpd
- Source Path /usr/sbin/httpd
- Port <Unknown>
- Host <Unknown>
- Source RPM Packages httpd-2.4.6-80.el7.centos.1.x86_64
- Target RPM Packages
- Policy RPM selinux-policy-3.13.1-192.el7_5.6.noarch
- Selinux Enabled True
- Policy Type targeted
- Enforcing Mode Permissive
- Host Name vm1
- Platform Linux vm1 3.10.0-862.11.6.el7.x86_64 #1 SMP Tue
- Aug 14 21:49:04 UTC 2018 x86_64 x86_64
- Alert Count 1
- First Seen 2018-09-10 08:09:45 UTC
- Last Seen 2018-09-10 08:09:45 UTC
- Local ID 4d40a98d-d33f-4a00-9ea8-661294094685
- Raw Audit Messages
- type=AVC msg=audit(1536566985.961:292): avc: denied { read } for pid=1524 comm="httpd" name="myapp.py" dev="sda1" ino=25292922 scontext=system_u:system_r:httpd_t:s0 tcontext=unconfined_u:object_r:var_t:s0 tclass=file
- type=AVC msg=audit(1536566985.961:292): avc: denied { open } for pid=1524 comm="httpd" path="/srv/myapp/myapp.py" dev="sda1" ino=25292922 scontext=system_u:system_r:httpd_t:s0 tcontext=unconfined_u:object_r:var_t:s0 tclass=file
- type=SYSCALL msg=audit(1536566985.961:292): arch=x86_64 syscall=open success=yes exit=ECHILD a0=557e0ed7ffc0 a1=80000 a2=1b6 a3=1 items=0 ppid=1521 pid=1524 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 tty=(none) ses=4294967295 comm=httpd exe=/usr/sbin/httpd subj=system_u:system_r:httpd_t:s0 key=(null)
- Hash: httpd,httpd_t,var_t,file,read
- [root@vm1 conf.d]# cd /srv/myapp/
- [root@vm1 myapp]# ll
- total 4
- -rwxr-x---. 1 apache apache 278 Sep 10 08:02 myapp.py
- [root@vm1 myapp]# ls -lZ
- -rwxr-x---. apache apache unconfined_u:object_r:var_t:s0 myapp.py
- [root@vm1 myapp]# yum install policycoreutils-{python,devel}
- Loaded plugins: fastestmirror
- Loading mirror speeds from cached hostfile
- * base: mirror.steadfastnet.com
- * epel: mirror.steadfastnet.com
- * extras: ftpmirror.your.org
- * updates: mirrors.liquidweb.com
- Package policycoreutils-python-2.5-22.el7.x86_64 already installed and latest version
- Resolving Dependencies
- --> Running transaction check
- ---> Package policycoreutils-devel.x86_64 0:2.5-22.el7 will be installed
- --> Processing Dependency: selinux-policy-devel for package: policycoreutils-devel-2.5-22.el7.x86_64
- --> Running transaction check
- ---> Package selinux-policy-devel.noarch 0:3.13.1-192.el7_5.6 will be installed
- --> Processing Dependency: m4 for package: selinux-policy-devel-3.13.1-192.el7_5.6.noarch
- --> Running transaction check
- ---> Package m4.x86_64 0:1.4.16-10.el7 will be installed
- --> Finished Dependency Resolution
- Dependencies Resolved
- =============================================================================================================================================================
- Package Arch Version Repository Size
- =============================================================================================================================================================
- Installing:
- policycoreutils-devel x86_64 2.5-22.el7 base 333 k
- Installing for dependencies:
- m4 x86_64 1.4.16-10.el7 base 256 k
- selinux-policy-devel noarch 3.13.1-192.el7_5.6 updates 1.7 M
- Transaction Summary
- =============================================================================================================================================================
- Install 1 Package (+2 Dependent packages)
- Total download size: 2.2 M
- Installed size: 24 M
- Is this ok [y/d/N]: y
- Downloading packages:
- (1/3): policycoreutils-devel-2.5-22.el7.x86_64.rpm | 333 kB 00:00:00
- (2/3): m4-1.4.16-10.el7.x86_64.rpm | 256 kB 00:00:00
- (3/3): selinux-policy-devel-3.13.1-192.el7_5.6.noarch.rpm | 1.7 MB 00:00:00
- -------------------------------------------------------------------------------------------------------------------------------------------------------------
- Total 4.7 MB/s | 2.2 MB 00:00:00
- Running transaction check
- Running transaction test
- Transaction test succeeded
- Running transaction
- Installing : m4-1.4.16-10.el7.x86_64 1/3
- Installing : policycoreutils-devel-2.5-22.el7.x86_64 2/3
- Installing : selinux-policy-devel-3.13.1-192.el7_5.6.noarch 3/3
- Verifying : m4-1.4.16-10.el7.x86_64 1/3
- Verifying : policycoreutils-devel-2.5-22.el7.x86_64 2/3
- Verifying : selinux-policy-devel-3.13.1-192.el7_5.6.noarch 3/3
- Installed:
- policycoreutils-devel.x86_64 0:2.5-22.el7
- Dependency Installed:
- m4.x86_64 0:1.4.16-10.el7 selinux-policy-devel.noarch 0:3.13.1-192.el7_5.6
- Complete!
- [root@vm1 myapp]# yum install bash-completion
- Loaded plugins: fastestmirror
- Loading mirror speeds from cached hostfile
- * base: mirror.steadfastnet.com
- * epel: mirror.steadfastnet.com
- * extras: ftpmirror.your.org
- * updates: mirrors.liquidweb.com
- Resolving Dependencies
- --> Running transaction check
- ---> Package bash-completion.noarch 1:2.1-6.el7 will be installed
- --> Finished Dependency Resolution
- Dependencies Resolved
- =============================================================================================================================================================
- Package Arch Version Repository Size
- =============================================================================================================================================================
- Installing:
- bash-completion noarch 1:2.1-6.el7 base 85 k
- Transaction Summary
- =============================================================================================================================================================
- Install 1 Package
- Total download size: 85 k
- Installed size: 259 k
- Is this ok [y/d/N]: y
- Downloading packages:
- bash-completion-2.1-6.el7.noarch.rpm | 85 kB 00:00:00
- Running transaction check
- Running transaction test
- Transaction test succeeded
- Running transaction
- Installing : 1:bash-completion-2.1-6.el7.noarch 1/1
- Verifying : 1:bash-completion-2.1-6.el7.noarch 1/1
- Installed:
- bash-completion.noarch 1:2.1-6.el7
- Complete!
- [root@vm1 myapp]# semanage fcontext -a -t httpd_sys_content_t "/srv/myapp(/.*)?"
- [root@vm1 myapp]# restorecon -RFvv /srv
- restorecon reset /srv/myapp context system_u:object_r:var_t:s0->system_u:object_r:httpd_sys_content_t:s0
- restorecon reset /srv/myapp/myapp.py context system_u:object_r:var_t:s0->system_u:object_r:httpd_sys_content_t:s0
- [root@vm1 myapp]# setenforce 0
- [root@vm1 myapp]# curl http://vm1.c.sixth-wave-179410.internal/myapp/
- Hello World![root@vm1 myapp]# cd /etc/httpd/conf.d/
- [root@vm1 conf.d]# vim virtual1.conf
- [root@vm1 conf.d]# systemctl restart httpd
- [root@vm1 conf.d]# curl http://vm1.c.sixth-wave-179410.internal/
- Hello World![root@vm1 conf.d]#
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement