gradm and Cpanel

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

gradm and Cpanel

Postby Ron » Wed Dec 07, 2005 7:42 pm

Hello,

After installing grsecurity everything is just kosher, enabling sysctl and installing gradm once enabled it cannot read the license, turn it off and works just fine, I did a quick search I didnt find much, any light to shed on the subject would be great :D
Ron
 
Posts: 4
Joined: Thu Nov 03, 2005 3:11 pm

Re: gradm and Cpanel

Postby PaX Team » Thu Dec 08, 2005 8:19 am

Ron wrote:After installing grsecurity everything is just kosher, enabling sysctl and installing gradm once enabled it cannot read the license, turn it off and works just fine, I did a quick search I didnt find much, any light to shed on the subject would be great :D
look at your grsec logs, maybe you can spot what access was denied. or strace it and see what fails that should work otherwise.
PaX Team
 
Posts: 2310
Joined: Mon Mar 18, 2002 4:35 pm

Postby Ron » Thu Dec 08, 2005 8:37 am

Im guessing this would be in /var/log/messages yes? I wont know till I can get into the noc i cant reach the system here at home, but the test system I have at home heres a link to the messages

http://stlhosting.com/messages.txt last 100 or so entries.. this system at home is redhat 9 the one im working on has centos 3.4 or 4.0 whichever I forgot im sure its a simple matter of enabling some files so it can have access to them but where and what im still learning this yet :) installing and compiling was fairly easy

Entire config http://stlhosting.com/.config-grsec
Ron
 
Posts: 4
Joined: Thu Nov 03, 2005 3:11 pm

Postby spender » Fri Dec 09, 2005 12:22 am

You've enabled the RBAC system but it doesn't seem like you've properly configured it yet. You should use the learning mode to generate a policy that will work on your system.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm

Postby Ron » Fri Dec 09, 2005 1:16 pm

Cool, heres what I get

gradm -F -L /var/log/learn.log
Duplicate subject found for "/etc/rc.d/init.d" in role default, on line 1 of (null).
"/etc/rc.d/init.d" references the same object as "/etc/init.d" specified on an earlier line.
The RBAC system will not load until this error is fixed.

CentOS release 3.6 (Final) btw
Ron
 
Posts: 4
Joined: Thu Nov 03, 2005 3:11 pm

Postby spender » Sun Dec 11, 2005 11:03 am

Remove the last line of the /etc/grsec/learn_config file:
inherit-learn /etc/rc.d/init.d

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm


Return to grsecurity support

cron