[CentOS] NOT Solved - Re: SELinux policy to allow Dovecot to connect to Mysql

Wed Apr 26 06:04:59 UTC 2017
Gordon Messmer <gordon.messmer at gmail.com>

On 04/25/2017 10:29 PM, Robert Moskowitz wrote:
> did not work.  it was set off, so I turned it on and tried it out. Got 
> the same errors:
> Apr 26 01:25:45 z9m9z dovecot: dict: Error: 
> mysql(/var/lib/mysql/mysql.sock): Connect failed to database 
> (postfix): Can't connect to local MySQL server through socket 
> '/var/lib/mysql/mysql.sock' (13) - waiting for 1 seconds before retry

OK.  Re-install the policy, "tail -f /var/log/audit/audit.log" and then 
try to use dovecot.  You're looking for an AVC.  What do you see?

> You would think that the mysql people would have a boolean to allow 
> specific apps to access the socket. 

That's not how SELinux works.  The policy on mysql doesn't control what 
clients do.  The clients have their own policies (or don't, many apps 
run unconfined).