View Issue Details

IDProjectCategoryView StatusLast Update
0000583AlmaLinux-9selinux-policypublic2025-11-21 05:42
Reporterpbiering Assigned To 
PriorityhighSeveritymajorReproducibilityalways
Status newResolutionopen 
Summary0000583: SELinux policy 38.1.65-1 breaks postfix tlsproxy
DescriptionSee https://issues.redhat.com/browse/RHEL-129917 assuming AlmaLinux has overtaken from RHEL 9.7

EL9.6 is still working.

# rpm -q selinux-policy selinux-policy-targeted
selinux-policy-38.1.53-5.el9_6.noarch
selinux-policy-targeted-38.1.53-5.el9_6.noarch

Update to EL9.7

# rpm -q selinux-policy selinux-policy-targeted
selinux-policy-38.1.65-1.el9.noarch
selinux-policy-targeted-38.1.65-1.el9.noarch

finally found an SELinux issue appearing now:

#============= postfix_smtp_t ==============
allow postfix_smtp_t postfix_master_t:tcp_socket setopt;

Looks like a change in the SELinux policy happened preventing now tlsproxy from proper working.
Steps To ReproduceSee https://issues.redhat.com/browse/RHEL-129917
TagsNo tags attached.

Activities

pbiering

2025-11-21 05:42

reporter   ~0001187

Sorry, forgot update, finally following is missing:

#============= postfix_smtp_t ==============
allow postfix_smtp_t postfix_master_t:tcp_socket { setopt read write };

Issue History

Date Modified Username Field Change
2025-11-21 05:41 pbiering New Issue
2025-11-21 05:42 pbiering Note Added: 0001187