Project

General

Profile

Bug #10443

Foreman cannot connect to OpenStack

Added by Lukas Zapletal over 5 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
High
Category:
Compute resources
Target version:
Difficulty:
Triaged:
Bugzilla link:
Fixed in Releases:
Found in Releases:

Description

We already attemted to fix this, but it looks like there are multiple ports we need to open.


Related issues

Related to SELinux - Bug #7346: Foreman can't connect to OpenStack port 5000Closed2014-09-04
Related to SELinux - Bug #15639: OpenStack 8774 port is not associated on RHEL6Closed2016-07-11

Associated revisions

Revision e54934d3 (diff)
Added by Lukas Zapletal over 4 years ago

Fixes #10443 - added OpenStack nova rules

This patch introduces new type for missing OpenStack port Compute
(Nova) on EL6, where no port type is provided.

History

#1 Updated by Lukas Zapletal over 5 years ago

  • Related to Bug #7346: Foreman can't connect to OpenStack port 5000 added

#2 Updated by Lukas Zapletal over 5 years ago

  • Category set to Compute resources
  • Bugzilla link set to 1136991

#3 Updated by The Foreman Bot over 5 years ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman-selinux/pull/45 added
  • Pull request deleted ()

#4 Updated by Lukas Zapletal over 4 years ago

  • Priority changed from Normal to High
  • Bugzilla link changed from 1136991 to 1318327

Associted with Satellite 6.2 BZ.

#5 Updated by Lukas Zapletal over 4 years ago

For the record, the AVC is:

time->Mon Apr 18 16:02:08 2016
type=SYSCALL msg=audit(1461009728.766:803): arch=c000003e syscall=42 success=no exit=-13 a0=14 a1=99f0738 a2=10 a3=f4f808 items=0 ppid=1 pid=26300 auid=4294967295 uid=997 gid=995 euid=997 suid=997 fsuid=997 egid=995 sgid=995 fsgid=995 tty=(none) ses=4294967295 comm="diagnostic_con*" exe="/opt/rh/rh-ruby22/root/usr/bin/ruby" subj=system_u:system_r:passenger_t:s0 key=(null)
type=AVC msg=audit(1461009728.766:803): avc:  denied  { name_connect } for  pid=26300 comm="diagnostic_con*" dest=8774 scontext=system_u:system_r:passenger_t:s0 tcontext=system_u:object_r:osapi_compute_port_t:s0 tclass=tcp_socket 

#6 Updated by Anonymous over 4 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100

#7 Updated by Dominic Cleal over 4 years ago

  • Legacy Backlogs Release (now unused) set to 155

#8 Updated by Dominic Cleal over 4 years ago

  • Related to Bug #15639: OpenStack 8774 port is not associated on RHEL6 added

Also available in: Atom PDF