store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Thu May 23, 2013 8:27 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 
Author Message
 Post subject: gradm-2.9-7
Unread postPosted: Tue May 15, 2012 2:40 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Just ran a yum upgrade for gradm-2.9-7 and it reported some warnings:

Code:
Updating   : gradm-2.9-7.el6.art.x86_64
Non-fatal <unknown> scriptlet failure in rpm package gradm-2.9-7.el6.art.x86_64
execstack: cannot open "/usr/lib*/python*/site-packages/_ctypes.so": No such file or directory
warning: %triggerin(gradm-2.9-7.el6.art.x86_64) scriptlet failed, exit status 1


Checked the RBAC policy for errors (these are warnings so not too bad):
Code:
gradm -C
Warning: object does not exist in role :::kernel:::, subject /sbin/halt for the target of the symlink object /sbin/halt specified on line 494 of /etc/grsec/policy.
Warning: object does not exist in role :::kernel:::, subject /lib64/ld-linux-x86-64.so.2 for the target of the symlink object /lib64/ld-linux-x86-64.so.2 specified on line 494 of /etc/grsec/policy.
Warning: object does not exist in role default, subject / for the target of the symlink object /dev/cdrom specified on line 305 of /etc/grsec/policy.
Warning: object does not exist in role default, subject /sbin/gradm_pam for the target of the symlink object /etc/localtime specified on line 282 of /etc/grsec/policy.
Warning: object does not exist in role shutdown, subject /sbin/gradm_pam for the target of the symlink object /etc/localtime specified on line 250 of /etc/grsec/policy.


Also checked the status (more worrying):
Code:
gradm -S
The /dev/grsec device is not properly installed on your system or you are not using a grsecurity kernel.


And the version installed (out of date?):
Code:
gradm -v
gradm v2.2.2


This leaves me confused, I'm not sure what I should be seeing, have never run these commands before.

If anyone can shed any light on this, I'd be most grateful.


Top
 Profile  
 
 Post subject: Re: gradm-2.9-7
Unread postPosted: Tue May 15, 2012 5:07 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Sounds like something happened with the upgrade, can you reinstall that upgrade?

yum reinstall gradm

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: gradm-2.9-7
Unread postPosted: Wed May 16, 2012 4:27 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Yup tried that, same result. Then noticed 2.9-8 in repo, ran yum upgrade gradm and still see:
Code:
Non-fatal <unknown> scriptlet failure in rpm package gradm-2.9-8.el6.art.x86_64
execstack: cannot open "/usr/lib*/python*/site-packages/_ctypes.so": No such file or directory
warning: %triggerin(gradm-2.9-8.el6.art.x86_64) scriptlet failed, exit status 1

But now:
Code:
gradm -v
gradm v2.9

So that seems to have updated OK, I guess the reported warnings are benign?
But:
Code:
gradm -S
The RBAC system is currently disabled.

So maybe not?


Top
 Profile  
 
 Post subject: Re: gradm-2.9-7
Unread postPosted: Thu May 17, 2012 5:17 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Which kernel are you running?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group