This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
Home Products Support Community News


Re: [Xen-API] problems with xen centre 5.6 fp1, xcp 1.0 and selinux

To: xen-api@xxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-API] problems with xen centre 5.6 fp1, xcp 1.0 and selinux
From: Magnus Therning <magnus.therning@xxxxxxxxxx>
Date: Wed, 9 Mar 2011 18:06:30 +0000
Delivery-date: Wed, 09 Mar 2011 10:06:42 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <AANLkTik1YZEbLh6m=HMVnJAR79eBWgjKHvoFBQwidED8@xxxxxxxxxxxxxx>
List-help: <mailto:xen-api-request@lists.xensource.com?subject=help>
List-id: Discussion of API issues surrounding Xen <xen-api.lists.xensource.com>
List-post: <mailto:xen-api@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-api>, <mailto:xen-api-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-api>, <mailto:xen-api-request@lists.xensource.com?subject=unsubscribe>
References: <AANLkTik1YZEbLh6m=HMVnJAR79eBWgjKHvoFBQwidED8@xxxxxxxxxxxxxx>
Sender: xen-api-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Mutt/1.5.21 (2010-09-15)
On Tue, Mar 08, 2011 at 12:22:07PM +0000, Chris Percol wrote:
> I know this question touches a lot of issues but here goes...
> I can't get connected to my xcp 1.0 pool using xen centre 5.6 fp1
> through a vpn connection if selinux is enabled in the host master
> CentOS OpenVPN guest.
> My vpn connects ok and I can ping the xcp 1.0 hosts but xen centre
> hangs when trying to login.
> Turning selinux off solves the problem but I would like to keep it on.
> Anyone any thoughts?

What do the logs say if you turn selinux on in non-enforcing mode?


Magnus Therning                            magnus.therning@xxxxxxxxxx
XenServer Security Lead

There does not now, nor will there ever, exist a programming language
in which it is the least bit hard to write bad programs.
     -- Flon's Axiom

I invented the term Object-Oriented, and I can tell you I did not have
C++ in mind.
     -- Alan Kay

xen-api mailing list

<Prev in Thread] Current Thread [Next in Thread>