Apache talking to MySQl issue in FC3 w/SE on

They have: 461 posts

Joined: Jul 2003

i have already been to http://fedora.redhat.com/docs/selinux-apache-fc3/

I used tha to get rid of the forbidden errors and set it up so that will not be an issue. however, i still have another issue: Apache is not allowed to talk to MySQL without policy modification.

i have certain constraints that require keeping SE on and applying itself to Apache, however, I may make a policy change that allows Apache and MySQL to talk.

i know that it's working aside from that. i can find ways to allow ssi, cgi, and some other things. i know they are inthe policy as default and how to edit that, but i do not know how to add one that allows MySQL calls from Apache

POSIX. because a stable os that doesn't have memory leaks and isn't buggy is always good.

mairving's picture

They have: 2,256 posts

Joined: Feb 2001

It would help if you could be a bit clearer about what you are talking about.

What is a policy modification in Apache?
Are you talking about changing httpd.conf?
Behind that you have to compile Apache with MySQL support. Most binaries would assume and do that for you.

Mark Irving
I have a mind like a steel trap; it is rusty and illegal in 47 states

They have: 461 posts

Joined: Jul 2003

it was compiled with mysql support.

have you used Fedora Core 2o ro 3 yet? SE is the security stuff from the redhat/nsa collaboration to make SE linux.

SE has some built in policies, but suppossivly one can write others. i dont know how to write them though. what i'm looking for is help in writing one that allows Apache and MySQL to talk. SE actually doesnt allow the mysql calls.

POSIX. because a stable os that doesn't have memory leaks and isn't buggy is always good.

Want to join the discussion? Create an account or log in if you already have one. Joining is fast, free and painless! We’ll even whisk you back here when you’ve finished.