Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Apparmor denial for ntpd on Focal #5795

Closed
2 tasks
kushaldas opened this issue Feb 17, 2021 · 1 comment · Fixed by #5806
Closed
2 tasks

Apparmor denial for ntpd on Focal #5795

kushaldas opened this issue Feb 17, 2021 · 1 comment · Fixed by #5806
Assignees

Comments

@kushaldas
Copy link
Contributor

Description

ntpd throws grsec denial message.

Steps to Reproduce

  • Install focal on hardware (I hope the same will show up in vm too)
  • check /var/log/syslog

Expected Behavior

  • no grsec error from ntpd

Actual Behavior


Feb 17 03:43:33 app systemd[1]: Starting Network Time Service... Feb 17 03:43:33 app kernel: [  202.428911] audit: type=1400 audit(1613533413.416:46): apparmor="DENIED" operation="open" profile="/usr/sbin/ntpd" name="/snap/bin/" pid=3303 comm="ntpd" requested_mask="r" denied_mask="r" fsuid=0 ouid=0 Feb 17 03:43:33 app ntpd[3303]: ntpd [email protected] (1): Starting Feb 17 03:43:33 app ntpd[3303]: Command line: /usr/sbin/ntpd -p /var/run/ntpd.pid -g -u 112:117 Feb 17 03:43:33 app ntpd[3306]: proto: precision = 0.175 usec (-22)
--

Comments

Suggestions to fix, any other relevant information.

@kushaldas kushaldas changed the title grsec denial for ntpd Apparmor denial for ntpd on Focal Feb 17, 2021
@conorsch
Copy link
Contributor

At standup today, @rmol mentioned he'd seen this one, too. Since we're adding ntp to Focal, conceivable we can just stop doing that, and let systemd-timesyncd do its thing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants