SELinux vs Postfix init script
Posted: 2017/08/01 14:25:16
Postfix itself (as in, the binary in /usr/sbin) runs just fine.
But when I do "service postfix start" it hangs for a sec and then fails without error or logging. Finally, come to realize SELinux is blocking the postfix init script's access to files it requires.
Now I could run to my SELinux modules directory and manually add additional policy to enable the use of the postfix init scripts (in addition to that which is already implemented for postfix itself). Or I could assume CentOS 6 is maintained by sane people who don't hate happiness, life, and all that is good in this world... a view I grow less certain of with each increasingly improbable eccentricity I face under CentOS 6... and thus wouldn't implement an SELinux policy that allows the postfix daemon to work but not the postfix init script used to manage the postfix daemon.
So... assuming this isn't a place so twisted and horrible that it makes 4chan seem like the home of equestrian sapients who believe friendship is magic... there must be a better, smarter. less brute-force-y solution. I await enlightenment with infinite eagerness.
But when I do "service postfix start" it hangs for a sec and then fails without error or logging. Finally, come to realize SELinux is blocking the postfix init script's access to files it requires.
Now I could run to my SELinux modules directory and manually add additional policy to enable the use of the postfix init scripts (in addition to that which is already implemented for postfix itself). Or I could assume CentOS 6 is maintained by sane people who don't hate happiness, life, and all that is good in this world... a view I grow less certain of with each increasingly improbable eccentricity I face under CentOS 6... and thus wouldn't implement an SELinux policy that allows the postfix daemon to work but not the postfix init script used to manage the postfix daemon.
So... assuming this isn't a place so twisted and horrible that it makes 4chan seem like the home of equestrian sapients who believe friendship is magic... there must be a better, smarter. less brute-force-y solution. I await enlightenment with infinite eagerness.