После рестарта начались проблемы с nginx и selinux. ошибка досутпа к ssl-pem файлам
restorecon -v -r /etc/nginx/ssl вроде стало рабоать
После отработал скрипт на обновление Ocsr перегрузкой nginx
После перезапуска службы тажа самая ошибка:
DOMAIN systemd[1]: Starting Session 439 of user root. -- Subject: Unit session-439.scope has begun start-up -- Defined-By: systemd -- Unit session-439.scope has begun starting up. Jun 08 06:30:02 DOMAIN CROND[16408]: (root) CMD (/usr/local/sbin/script.sh) Jun 08 06:30:02 DOMAIN CROND[16409]: (root) CMD (/usr/local/bin/script.pl >/dev/null) Jun 08 06:31:31 DOMAIN sshd[16419]: Connection closed by 10.1.1.1 [preauth] Jun 08 06:33:47 DOMAIN run-parts(/etc/cron.daily)[16518]: starting refresh-ocsp Jun 08 06:33:56 DOMAIN systemd[1]: Stopping nginx - high performance web server...
-- Subject: Unit nginx.service has begun shutting down -- Defined-By: systemd -- Unit nginx.service has begun shutting down. Jun 08 06:33:56 DOMAIN systemd[1]: Starting nginx - high performance web server... -- Subject: Unit nginx.service has begun start-up -- Defined-By: systemd
-- Unit nginx.service has begun starting up. Jun 08 06:33:56 DOMAIN nginx[16568]: nginx: [emerg] BIO_new_file(«/etc/nginx/ssl/CLIENT-ocsp.pem») failed (SSL: error:0200100D:system library:fopen:Permission den Jun 08 06:33:56 DOMAIN nginx[16568]: nginx: configuration file /etc/nginx/nginx.conf test failed Jun 08 06:33:56 DOMAIN systemd[1]: nginx.service: control process exited, code=exited status=1 Jun 08 06:33:56 DOMAIN systemd[1]: Failed to start nginx - high performance web server. -- Subject: Unit nginx.service has failed -- Unit nginx.service has failed.
После restorecon -R -v /etc/nginx/ssl/*.pem после nginx запустился
Куда смотреть? ПРодакшн сервер, у меня первые недели на этой работе... много своих приколов Aпач и fpm на другой ВМ, на это только прокси
Общее: [root@domain etc]# ausearch -m avc -ts today | audit2allow
#============= httpd_t ==============
#!!!! WARNING 'httpd_t' is not allowed to write or create to var_run_t. Change the label to httpd_var_run_t. allow httpd_t var_run_t:file { read write };