Re: [SLE] DNS server - persmissions problem



Sunny wrote:

Now, when I start the DNS slave, in the log files I see:

May 22 12:46:29 fwqa named[20985]: zone mydomain.com/IN: Transfer
started. May 22 12:46:29 fwqa named[20985]: transfer of
'mydomain.com/IN' from 10.88.2.11#53: connected using 10.88.3.11#44250
May 22 12:46:29 fwqa named[20985]: dumping master file: rename:
slave/mydomain.com: permission denied
May 22 12:46:29 fwqa named[20985]: transfer of 'mydomain.com/IN' from
10.88.2.11#53: failed while receiving responses: permission denied
May 22 12:46:29 fwqa named[20985]: transfer of 'mydomain.com/IN' from
10.88.2.11#53: end of transfer
May 22 12:46:29 fwqa kernel: audit(1148319989.417:73): REJECTING w
access to /slave/mydomain.com (named(20986) profile /usr/sbin/named
active /usr/sbin/named)

This is auditd creating a problem - to start with you can turn the
REJECTs into warnings by issuing "complain /usr/sbin/named".
Alternatively, you can update the apparmor profile by issuing
"aa-genprof /usr/sbin/named".


/Per Jessen, Zürich


--
Check the headers for your unsubscription address
For additional commands send e-mail to suse-linux-e-help@xxxxxxxx
Also check the archives at http://lists.suse.com
Please read the FAQs: suse-linux-e-faq@xxxxxxxx