<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SELinux Blocking ip from read/open on libjsig.so in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/selinux-blocking-ip-from-read-open-on-libjsig-so/m-p/167111#M6630</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume you want SELinux to remain enabled and probably don't want it in permissive mode. If so, then I think the other other option would be to make an exception for the process by flagging it with the unconfined option. I'm not 100% positive on what the proper place to configure that would be. Possibly you would just throw this line into the systemd service itself:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;SELinuxContext=system_u:system_r:unconfined_t:s0 &lt;/CODE&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 May 2019 04:29:54 GMT</pubDate>
    <dc:creator>EarlMedina</dc:creator>
    <dc:date>2019-05-22T04:29:54Z</dc:date>
    <item>
      <title>SELinux Blocking ip from read/open on libjsig.so</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/selinux-blocking-ip-from-read-open-on-libjsig-so/m-p/167110#M6629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm running ArcGIS Server 10.7 on RHEL Server 7.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whenever I start ArcGIS Server with the systemd unit included in the install, copied from arcgis/server/framework/etc/scripts/ to /etc/systemd/system/arcgisserver.service, it gives SELinux alerts blocking&amp;nbsp;read/open on libjsig.so and libprejsig.so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I start ArcGIS Server by directly calling startserver.sh, There are no alerts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attempted to install local policy allowing access using audit2allow via this guide:&amp;nbsp;&lt;A href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security-enhanced_linux/sect-security-enhanced_linux-fixing_problems-allowing_access_audit2allow"&gt;https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security-enhanced_linux/sect-security-enhanced_linux-fixing_problems-allowing_access_audit2allow&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and also in the RHEL SELinux Troubleshooter instructions:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;# ausearch -c 'ip' --raw | audit2allow -M my-ip&lt;/P&gt;&lt;P&gt;# semodule -i my-ip.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also tried adjusting the file's context with:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;# semanage fcontext -a -t default_t&amp;nbsp;libjsig.so&lt;/P&gt;&lt;P&gt;# restorecon -v libjsig.so&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I start ArcGIS Server through systemd without the SELinux permission errors?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 May 2019 16:12:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/selinux-blocking-ip-from-read-open-on-libjsig-so/m-p/167110#M6629</guid>
      <dc:creator>BenRomlein</dc:creator>
      <dc:date>2019-05-21T16:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: SELinux Blocking ip from read/open on libjsig.so</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/selinux-blocking-ip-from-read-open-on-libjsig-so/m-p/167111#M6630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume you want SELinux to remain enabled and probably don't want it in permissive mode. If so, then I think the other other option would be to make an exception for the process by flagging it with the unconfined option. I'm not 100% positive on what the proper place to configure that would be. Possibly you would just throw this line into the systemd service itself:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;SELinuxContext=system_u:system_r:unconfined_t:s0 &lt;/CODE&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2019 04:29:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/selinux-blocking-ip-from-read-open-on-libjsig-so/m-p/167111#M6630</guid>
      <dc:creator>EarlMedina</dc:creator>
      <dc:date>2019-05-22T04:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: SELinux Blocking ip from read/open on libjsig.so</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/selinux-blocking-ip-from-read-open-on-libjsig-so/m-p/167112#M6631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, Earl.&lt;/P&gt;&lt;P&gt;I tried adding that line to my unit file in various places but none have yet solved the problem.&lt;/P&gt;&lt;P&gt;Adding it in the [Unit] or [Install] Section, the service can start successfully, but SELinux still alerts about libjsig.so.&lt;/P&gt;&lt;P&gt;Adding it to the [Service] Section, starting the service fails with SELinux denying transition on the startserver.sh script.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a specific order the lines in my unit file have to be arranged?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the current contents of the file:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sudo cat /etc/systemd/system/arcgisserver.service :&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;# ------------------------------------------------------------------&lt;BR /&gt;# ArcGIS Server systemd unit file&lt;BR /&gt;# ------------------------------------------------------------------&lt;BR /&gt;#&lt;BR /&gt;# Configure ArcGIS Server to be started at boot on Linux distributions&lt;BR /&gt;# adopting systemd init system (For example RHEL 7.x and SuSE12) by&lt;BR /&gt;# following these instructions:&lt;BR /&gt;#&lt;BR /&gt;# 1.) Switch to the root user.&lt;BR /&gt;#&lt;BR /&gt;# 2.) Copy this file to /etc/systemd/system&lt;BR /&gt;#&lt;BR /&gt;# 3.) Enable the service to start at boot:&lt;BR /&gt;#&lt;BR /&gt;# # systemctl enable arcgisserver.service&lt;BR /&gt;#&lt;BR /&gt;# 4.) Verify systemd service is setup correctly:&lt;BR /&gt;#&lt;BR /&gt;# # systemctl stop arcgisserver.service&lt;BR /&gt;# # systemctl start arcgisserver.service&lt;BR /&gt;# # systemctl status arcgisserver.service&lt;BR /&gt;#&lt;BR /&gt;# 5.) Reboot the system and verify that Server restarts properly.&lt;BR /&gt;#&lt;BR /&gt;# ------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Unit]&lt;BR /&gt;Description=ArcGIS Server Service&lt;BR /&gt;After=network.target&lt;/P&gt;&lt;P&gt;SELinuxContext=system_u:system_r:unconfined_t:s0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Service]&lt;BR /&gt;Type=forking&lt;BR /&gt;User=igsgis&lt;BR /&gt;GuessMainPID=false&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# The minimum number of processes need to be set to 25059 or higher. Enable&lt;BR /&gt;# and raise this limit if it is a heavily used system. Use ulimit -Su -Hu to&lt;BR /&gt;# check current values.&lt;BR /&gt;# LimitNPROC=25059&lt;BR /&gt;# LimitNOFILE=65535&lt;/P&gt;&lt;P&gt;# To prevent any one service from spawning too many threads and consuming all&lt;BR /&gt;# server resources, systemd v228 and beyond included in SLES12 SP2 and higher&lt;BR /&gt;# set the maximum number of threads to be created at 512. Users on SLES12 may&lt;BR /&gt;# need to enable and raise this limit if it is a heavily used system. Use&lt;BR /&gt;# "systemctl show --property DefaultTasksMax" to check the current value. To&lt;BR /&gt;# find the version of systemd, use "systemctl --version".&lt;BR /&gt;# TasksMax=512&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ExecStart=/diskarray/arcgis/server/startserver.sh&lt;BR /&gt;ExecStop=/diskarray/arcgis/server/stopserver.sh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install]&lt;BR /&gt;WantedBy=multi-user.target&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks again for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EDIT:&lt;/P&gt;&lt;P&gt;This is the output of ls -Z for the two files throwing the error:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;-rwx------. igsgis data unconfined_u:object_r:unlabeled_t:s0 libjsig.so&lt;/P&gt;&lt;P&gt;-rwx------. igsgis data unconfined_u:object_r:unlabeled_t:s0 libprejsig.so&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;(As mentioned earlier, I've tried switching context type to default as well, I've also tried switching user from unconfined to system)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SELinux Alerts are:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;SELinux is preventing /usr/sbin/ip from open access on the file /diskarray/arcgis/server/framework/runtime/jre/lib/libprejsig.so.&lt;/P&gt;&lt;P&gt;SELinux is preventing /usr/sbin/ip from getattr access on the file /diskarray/arcgis/server/framework/runtime/jre/lib/libjsig.so.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2019 12:33:55 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/selinux-blocking-ip-from-read-open-on-libjsig-so/m-p/167112#M6631</guid>
      <dc:creator>BenRomlein</dc:creator>
      <dc:date>2019-05-22T12:33:55Z</dc:date>
    </item>
  </channel>
</rss>

