apache and httpd_can_network_connect_db
apache and httpd_can_network_connect_db
How to add port of MSSQL(1433) to httpd_can_network_connect_db or add some changes in apache policy? I know about httpd_can_network_connect but this is not my way.
apache and httpd_can_network_connect_db
have you checked SELinux attributes ?
[code]getsebool -a | grep httpd[/code]
[code]getsebool -a | grep httpd[/code]
Re: apache and httpd_can_network_connect_db
httpd_can_network_connect_db and httpd_can_network_connect is off
Re: apache and httpd_can_network_connect_db
and if you turn them up (setsebool) ? will it work ?
Re: apache and httpd_can_network_connect_db
httpd_can_network_connect-db 1 - don't work
httpd_can_network_connect - work, but it's not good for security reason
httpd_can_network_connect - work, but it's not good for security reason
Re: apache and httpd_can_network_connect_db
If you want to add a non standard port to mysql SELinux policy
you may need to use [b]semanage[/b] for that
[code][root@example ~]# semanage port -l | grep mysql
mysqld_port_t tcp 1186, 3306
and now adding ports is done with
[root@example ~]# semanage port -a -t mysqld_port_t -p tcp 1433
verify with
[root@example ~]# semanage port -l | grep mysql
mysqld_port_t tcp 1433, 1186, 3306[/code]
same way is with http .
hope this can help you
please provide avc error from logs for resolving SELinux problems
you may need to use [b]semanage[/b] for that
[code][root@example ~]# semanage port -l | grep mysql
mysqld_port_t tcp 1186, 3306
and now adding ports is done with
[root@example ~]# semanage port -a -t mysqld_port_t -p tcp 1433
verify with
[root@example ~]# semanage port -l | grep mysql
mysqld_port_t tcp 1433, 1186, 3306[/code]
same way is with http .
hope this can help you
please provide avc error from logs for resolving SELinux problems
Re: apache and httpd_can_network_connect_db
Thanks, this is good idea.