nixCraft Linux Forum

nixCraft

Linux / UNIX Tech Support Forum

SELinux and DNS Issues

This is a discussion on SELinux and DNS Issues within the Domain Name Server forums, part of the Mastering Servers category; Hello, I recently became the administrator of the primary and secondary DNS servers of a local ISP. Both of the ...


Go Back   nixCraft Linux Forum > Mastering Servers > Domain Name Server

Linux answers from nixCraft.


Domain Name Server Discussion on domain name server including BIND and other servers.

Reply

 

LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 13-11-2008, 09:14 PM
Junior Member
User
 
Join Date: Nov 2008
OS: Redhat Enterprise 5, Centos 5
Posts: 8
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
jgijanto is on a distinguished road
Default SELinux and DNS Issues

Hello,

I recently became the administrator of the primary and secondary DNS servers of a local ISP. Both of the name servers are running BIND 9.3 on RedHat Enterprise Linux Server 5.2, and have been running without problems until now.

In trying to troubleshoot an issue with another server, I backed up named.conf, modified the acl, and restarted the service. Now I am seeing messages in /var/log/messages that look like this:

Nov 13 11:21:48 ns3 setroubleshoot: SELinux is preventing named (named_t) "setattr" to ./db.example (named_zone_t). For complete SELinux messages. run sealert -l 03c8f88e-c6cd-4111-a6ad-738362ae00fd
Nov 13 11:21:48 ns3 setroubleshoot: SELinux is preventing named (named_t) "setattr" to ./db.example2 (named_zone_t). For complete SELinux messages. run sealert -l 210fbc71-e802-4b5f-b271-aa5e5bdf52c8
Nov 13 11:21:48 ns3 named[3434]: zone domain.com/IN: refresh: could not set file modification time of 'db.domain': permission denied
Nov 13 11:21:49 ns3 named[3434]: zone domain2.com/IN: refresh: could not set file modification time of 'db.domain2': permission denied
Nov 13 11:21:49 ns3 named[3434]: zone domain3.com/IN: refresh: could not set file modification time of 'db.domain3': permission denied


There seems to be a similar message to this for every resolve query. I've tried restoring the old named.conf and disabling SELinux, however the log fills with different error messages. Since it didn't solve the issue, I was hesitant to leave the server running for long without SELinux running, so I turned it back on and rebooted again.

At the moment we aren't experiencing any outages, since the primary nameserver is functioning fine, but any thoughts on the matter would be very much appreciated .

Thanks,
Joe
Reply With Quote
  #2 (permalink)  
Old 13-11-2008, 10:39 PM
Junior Member
User
 
Join Date: Nov 2008
OS: Redhat Enterprise 5, Centos 5
Posts: 8
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
jgijanto is on a distinguished road
Default

Well, we resolved the problem.

It appears that the rules in iptables were modified, and that traffic on port 53 was being blocked. Allowing this traffic and restarting iptables restored functionality of the server.
Reply With Quote
  #3 (permalink)  
Old 14-11-2008, 12:49 AM
nixcraft's Avatar
Never say die
User
 
Join Date: Jan 2005
Location: BIOS
OS: RHEL
Scripting language: Bash and Python
Posts: 2,710
Thanks: 11
Thanked 244 Times in 183 Posts
Rep Power: 10
nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute
Default

Also, you may want to turn on iptables log facility to detect such problem in advance.
__________________
Vivek Gite
Linux Evangelist
Be proud RHEL user, and let the world know about your enterprise choices! Join RedHat user group.
Always use CODE tags for posting system output and commands!
Do you run a Linux? Let's face it, you need help
Reply With Quote
Reply

Tags
bind , iptables , named , selinux


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads

Thread Thread Starter Forum Replies Last Post
Firewall issues shilpigoel1 Networking, Firewalls and Security 3 30-10-2007 03:47 AM


All times are GMT +5.5. The time now is 11:43 PM.


Powered by vBulletin® Version 3.8.5 - Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2
©2005-2010 nixCraft. All rights reserved

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38