<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Apache startup failed (points!) in Linux-Based Community / Regional</title>
    <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722153#M71</link>
    <description>After applying the restorecon fix commands (see my previous post) now I get the following messages in /var/log/messages:&lt;BR /&gt;&lt;BR /&gt;Dec  8 12:02:11 smarty dbus: avc:  received setenforce notice (enforcing=1)&lt;BR /&gt;Dec  8 12:02:11 smarty dbus: avc:  received setenforce notice (enforcing=1)&lt;BR /&gt;Dec  8 12:02:11 smarty dbus: Can't send to audit system: USER_AVC avc:  received setenforce notice (enforcing=1)#012: exe="?" sauid=81 hostname=? addr=? terminal=?&lt;BR /&gt;Dec  8 12:02:11 smarty dbus: [system] Reloaded configuration&lt;BR /&gt;Dec  8 12:04:23 smarty dbus: avc:  received setenforce notice (enforcing=0)&lt;BR /&gt;Dec  8 12:04:23 smarty dbus: avc:  received setenforce notice (enforcing=0)&lt;BR /&gt;Dec  8 12:04:23 smarty dbus: Can't send to audit system: USER_AVC avc:  received setenforce notice (enforcing=0)#012: exe="?" sauid=81 hostname=? addr=? terminal=?&lt;BR /&gt;Dec  8 12:05:37 smarty dbus: avc:  received setenforce notice (enforcing=1)&lt;BR /&gt;Dec  8 12:05:37 smarty dbus: avc:  received setenforce notice (enforcing=1)&lt;BR /&gt;Dec  8 12:05:37 smarty dbus: Can't send to audit system: USER_AVC avc:  received setenforce notice (enforcing=1)#012: exe="?" sauid=81 hostname=? addr=? terminal=?&lt;BR /&gt;Dec  8 12:05:37 smarty dbus: [system] Reloaded configuration&lt;BR /&gt;&lt;BR /&gt;Behaviour with SELinux is now:&lt;BR /&gt;&lt;BR /&gt;Enforced mode: web page is not served (0 bytes are served)&lt;BR /&gt;Permissive mode: everything is fine&lt;BR /&gt;&lt;BR /&gt;If you want me to try any more tweaks with SELinux you can give me some hints.&lt;BR /&gt;&lt;BR /&gt;Christian</description>
    <pubDate>Wed, 08 Dec 2010 11:21:45 GMT</pubDate>
    <dc:creator>Christian Deutsch_1</dc:creator>
    <dc:date>2010-12-08T11:21:45Z</dc:date>
    <item>
      <title>Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722134#M52</link>
      <description>Hi there,&lt;BR /&gt;&lt;BR /&gt;Somewhat over a year ago I successfully configured apache httpd to work on a RHEL 5.3 system. Now I have Fedora 13 and startup of Apache httpd failed:&lt;BR /&gt;&lt;BR /&gt;service httpd --full-restart&lt;BR /&gt;Stopping httpd:                        [FAILED]&lt;BR /&gt;Starting httpd:                        [FAILED]&lt;BR /&gt;&lt;BR /&gt;I tried `chkconfig httpd on` and that returned no error message but still full-restart and also start failed.&lt;BR /&gt;&lt;BR /&gt;Where to look?&lt;BR /&gt;&lt;BR /&gt;If I posted in the wrong section please tell me where to post this question.&lt;BR /&gt;&lt;BR /&gt;I already configured apache so hopefully configuration is correct.&lt;BR /&gt;&lt;BR /&gt;Helpful answers will be rewarded generously with points!&lt;BR /&gt;&lt;BR /&gt;Thanks, Christian</description>
      <pubDate>Mon, 06 Dec 2010 13:33:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722134#M52</guid>
      <dc:creator>Christian Deutsch_1</dc:creator>
      <dc:date>2010-12-06T13:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722135#M53</link>
      <description>go to /etc/httpd/logs&lt;BR /&gt;&lt;BR /&gt;check error_log&lt;BR /&gt;&lt;BR /&gt;post logs.&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Dec 2010 14:59:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722135#M53</guid>
      <dc:creator>Alzhy</dc:creator>
      <dc:date>2010-12-06T14:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722136#M54</link>
      <description>ll /etc/httpd/logs&lt;BR /&gt;lrwxrwxrwx. 1 root root 19 Oct  6 09:39 /etc/httpd/logs -&amp;gt; ../../var/log/httpd&lt;BR /&gt;[root@smarty httpd]# ls /etc/httpd/logs&lt;BR /&gt;[root@smarty httpd]# ll /var/log/httpd&lt;BR /&gt;total 0&lt;BR /&gt;&lt;BR /&gt;now what?&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Dec 2010 15:04:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722136#M54</guid>
      <dc:creator>Christian Deutsch_1</dc:creator>
      <dc:date>2010-12-06T15:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722137#M55</link>
      <description>Are you using the default httpd.conf still? If not - can you re-instate the original httpd.conf and try a start?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Or if you can just whack your existing http installation and re-install from yum repository.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Dec 2010 15:10:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722137#M55</guid>
      <dc:creator>Alzhy</dc:creator>
      <dc:date>2010-12-06T15:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722138#M56</link>
      <description>&lt;!--!*#--&gt;&amp;gt; Somewhat over a year ago I successfully&lt;BR /&gt;&amp;gt; configured apache httpd to work on a RHEL&lt;BR /&gt;&amp;gt; 5.3 system. Now I have Fedora 13 and&lt;BR /&gt;&amp;gt; startup of Apache httpd failed:&lt;BR /&gt;&lt;BR /&gt;Is this "Fedora 13" system the same one as&lt;BR /&gt;the "RHEL 5.3" system?  So, did you replace&lt;BR /&gt;the OS, but _not_ re-install Apache?  If so,&lt;BR /&gt;then this advice sounds good to me:&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Or if you can just whack your existing http&lt;BR /&gt;&amp;gt; installation and re-install from yum&lt;BR /&gt;&amp;gt; repository.&lt;BR /&gt;&lt;BR /&gt;And probably any number of other optional&lt;BR /&gt;products, too.  You might be able to save the&lt;BR /&gt;Apache configuration files from the old&lt;BR /&gt;installation, unless the new Apache version&lt;BR /&gt;differs too much from the old one.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Helpful answers will be rewarded generously&lt;BR /&gt;&amp;gt; with points!&lt;BR /&gt;&lt;BR /&gt;What's that worth in US$?</description>
      <pubDate>Mon, 06 Dec 2010 15:30:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722138#M56</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2010-12-06T15:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722139#M57</link>
      <description>Uninstalled httpd, installed:&lt;BR /&gt;&lt;BR /&gt;httpd-2.2.17-1.fc13.1.x86_64&lt;BR /&gt;&lt;BR /&gt;ll /etc/httpd/conf/httpd.conf&lt;BR /&gt;-rw-r--r--. 1 root root 33738 Oct 27 14:26 /etc/httpd/conf/httpd.conf&lt;BR /&gt;&lt;BR /&gt;service httpd start&lt;BR /&gt;Starting httpd:                       [FAILED]&lt;BR /&gt;&lt;BR /&gt;ll /etc/httpd/logs&lt;BR /&gt;lrwxrwxrwx. 1 root root 19 Dec  6 16:20 /etc/httpd/logs -&amp;gt; ../../var/log/httpd&lt;BR /&gt;[root@smarty httpd]# ls /etc/httpd/logs&lt;BR /&gt;[root@smarty httpd]# ll /var/log/httpd&lt;BR /&gt;total 0&lt;BR /&gt;&lt;BR /&gt;Thanks, Christian</description>
      <pubDate>Mon, 06 Dec 2010 15:32:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722139#M57</guid>
      <dc:creator>Christian Deutsch_1</dc:creator>
      <dc:date>2010-12-06T15:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722140#M58</link>
      <description>Steve:&lt;BR /&gt;&lt;BR /&gt;Same hardware and hostname but now ext4 filesystems with encryption, before I had ext3 without encryption. I did not adopt any httpd configuration from the previous installation.&lt;BR /&gt;&lt;BR /&gt;Christian</description>
      <pubDate>Mon, 06 Dec 2010 15:35:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722140#M58</guid>
      <dc:creator>Christian Deutsch_1</dc:creator>
      <dc:date>2010-12-06T15:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722141#M59</link>
      <description>Encryption?&lt;BR /&gt;&lt;BR /&gt;I think that may very well be where your issue is?&lt;BR /&gt;&lt;BR /&gt;What ext4 filesystems did you enable encryption on? Did you incldue /var by any chace in your ext4 encryption? And does user apache have access to those encyrpted filesystems?&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Dec 2010 15:38:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722141#M59</guid>
      <dc:creator>Alzhy</dc:creator>
      <dc:date>2010-12-06T15:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722142#M60</link>
      <description>all filesystems should be "transparent" for encryption:&lt;BR /&gt;&lt;BR /&gt;df -h&lt;BR /&gt;Filesystem            Size  Used Avail Use% Mounted on&lt;BR /&gt;/dev/mapper/luks-51cdeaa5-41c2-400f-aeae-b1b5323e6d7a&lt;BR /&gt;                       50G  8.3G   39G  18% /&lt;BR /&gt;tmpfs                 6.0G  3.6M  6.0G   1% /dev/shm&lt;BR /&gt;/dev/sda1             485M   28M  432M   7% /boot&lt;BR /&gt;/dev/mapper/luks-f8ae7a61-a4ef-41aa-92a3-7c67a1fc5043&lt;BR /&gt;                     1001G  118G  833G  13% /home&lt;BR /&gt;&lt;BR /&gt;1 filesystem and disk for /. /boot is also on that disk and part of /home. Only the rest of /home is on the second disk.&lt;BR /&gt;&lt;BR /&gt;I cannot see an issue with file systems or encryption here.&lt;BR /&gt;&lt;BR /&gt;Christian</description>
      <pubDate>Tue, 07 Dec 2010 07:32:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722142#M60</guid>
      <dc:creator>Christian Deutsch_1</dc:creator>
      <dc:date>2010-12-07T07:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722143#M61</link>
      <description>Have you tried to check if the syntax of the httpd.conf is correct?&lt;BR /&gt;#/usr/sbin/httpd -t   ==&amp;gt; should say syntax OK&lt;BR /&gt;&lt;BR /&gt;or #/usr/sbin/apache-perl -T&lt;BR /&gt;&lt;BR /&gt;or #apachectl configtest &lt;BR /&gt;</description>
      <pubDate>Tue, 07 Dec 2010 10:53:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722143#M61</guid>
      <dc:creator>Chhaya_Z</dc:creator>
      <dc:date>2010-12-07T10:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722144#M62</link>
      <description>Wow Chhaya,&lt;BR /&gt;&lt;BR /&gt;That brings me forward! Thank you so much!&lt;BR /&gt;&lt;BR /&gt;So far I identified a problem with a file that I added:&lt;BR /&gt;&lt;BR /&gt;/etc/httpd/conf.d/ssl.conf&lt;BR /&gt;&lt;BR /&gt;Into this file I put:&lt;BR /&gt;&lt;BR /&gt;SSLCertificateFile /etc/pki/tls/certs/localhost.crt&lt;BR /&gt;SSLCertificateKeyFile /etc/pki/tls/private/localhost.key&lt;BR /&gt;&lt;BR /&gt;This is the cause of the fail.&lt;BR /&gt;&lt;BR /&gt;In an older version of httpd (httpd-2.2.3-19.el5), this worked fine.&lt;BR /&gt;&lt;BR /&gt;Any idea what is different in version httpd-2.2.17-1.fc13.1.x86_64 such that I get this error when I have these values in ssl.conf?&lt;BR /&gt;&lt;BR /&gt;/usr/sbin/httpd -t&lt;BR /&gt;Syntax error on line 1 of /etc/httpd/conf.d/ssl.conf:&lt;BR /&gt;Invalid command 'SSLCertificateFile', perhaps misspelled or defined by a module not included in the server configuration&lt;BR /&gt;&lt;BR /&gt;Thanks for further help if possible. Of course more points will come :)&lt;BR /&gt;&lt;BR /&gt;Christian</description>
      <pubDate>Tue, 07 Dec 2010 12:40:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722144#M62</guid>
      <dc:creator>Christian Deutsch_1</dc:creator>
      <dc:date>2010-12-07T12:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722145#M63</link>
      <description>Dear Christian.&lt;BR /&gt;&lt;BR /&gt;Are you sure you have "mod_ssl" module loaded?  Verify with:&lt;BR /&gt;&lt;BR /&gt;apache2ctl -M&lt;BR /&gt;&lt;BR /&gt;The directive "SSLCertificateFile" is still valid for this module.</description>
      <pubDate>Tue, 07 Dec 2010 12:50:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722145#M63</guid>
      <dc:creator>Goran Koruga</dc:creator>
      <dc:date>2010-12-07T12:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722146#M64</link>
      <description>Thanks Goran,&lt;BR /&gt;&lt;BR /&gt;I am making some more progress now!&lt;BR /&gt;&lt;BR /&gt;So now I installed:&lt;BR /&gt;&lt;BR /&gt;mod_ssl-2.2.17-1.fc13.1.x86_64&lt;BR /&gt;&lt;BR /&gt;/usr/sbin/httpd -t shows:&lt;BR /&gt;&lt;BR /&gt;Syntax OK&lt;BR /&gt;&lt;BR /&gt;But:&lt;BR /&gt;&lt;BR /&gt;/usr/sbin/apachectl -M&lt;BR /&gt;&lt;BR /&gt;returns no text and error code 1&lt;BR /&gt;&lt;BR /&gt;And:&lt;BR /&gt;&lt;BR /&gt;service httpd --full-restart&lt;BR /&gt;Stopping httpd:                                            [  OK  ]&lt;BR /&gt;Starting httpd:                                            [FAILED]&lt;BR /&gt;&lt;BR /&gt;Some more helpful ideas? (I could not find apache2ctl so I tried /usr/sbin/apachectl instead).&lt;BR /&gt;&lt;BR /&gt;Thanks, Christian&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 07 Dec 2010 13:20:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722146#M64</guid>
      <dc:creator>Christian Deutsch_1</dc:creator>
      <dc:date>2010-12-07T13:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722147#M65</link>
      <description>Is SElinux Enabled?</description>
      <pubDate>Tue, 07 Dec 2010 13:22:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722147#M65</guid>
      <dc:creator>Chhaya_Z</dc:creator>
      <dc:date>2010-12-07T13:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722148#M66</link>
      <description>Christian,&lt;BR /&gt;&lt;BR /&gt;Please check the messages file for any errors while starting the httpd service&lt;BR /&gt;&lt;BR /&gt;#tailf /var/log/messages&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 07 Dec 2010 13:34:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722148#M66</guid>
      <dc:creator>Chhaya_Z</dc:creator>
      <dc:date>2010-12-07T13:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722149#M67</link>
      <description>Wow Chhaya!&lt;BR /&gt;&lt;BR /&gt;Great work!&lt;BR /&gt;&lt;BR /&gt;Now `/usr/sbin/apachectl -M` shows me the modules being loaded.&lt;BR /&gt;&lt;BR /&gt;And `service httpd --full-restart` started httpd ok.&lt;BR /&gt;&lt;BR /&gt;I changed SELinux Default and Current Enforcing Mode to Permissive. I was not aware that in Fedora 13 it seems that SELinux is enabled by default.&lt;BR /&gt;&lt;BR /&gt;Now apache is running, let me see if everything else works as expected...&lt;BR /&gt;&lt;BR /&gt;Thanks, Christian</description>
      <pubDate>Tue, 07 Dec 2010 13:34:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722149#M67</guid>
      <dc:creator>Christian Deutsch_1</dc:creator>
      <dc:date>2010-12-07T13:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722150#M68</link>
      <description>Christian,&lt;BR /&gt;&lt;BR /&gt;If you want to get Apache working when SElinux is enabled then you have to set a boolean. &lt;BR /&gt;&lt;BR /&gt;you can try the below step&lt;BR /&gt;&lt;BR /&gt;#setsebool â  P httpd_disable_trans 1&lt;BR /&gt;Now restart the service and it should work fine.&lt;BR /&gt;&lt;BR /&gt;I am glad that its working. It was my pleasure assisting you :)&lt;BR /&gt;&lt;BR /&gt;Have a great day ahead.</description>
      <pubDate>Tue, 07 Dec 2010 13:40:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722150#M68</guid>
      <dc:creator>Chhaya_Z</dc:creator>
      <dc:date>2010-12-07T13:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722151#M69</link>
      <description>In my previous response plz ignore those special characters in the command. It has to be as below&lt;BR /&gt;&lt;BR /&gt;#setsebool -P httpd_disable_trans 1</description>
      <pubDate>Tue, 07 Dec 2010 13:56:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722151#M69</guid>
      <dc:creator>Chhaya_Z</dc:creator>
      <dc:date>2010-12-07T13:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722152#M70</link>
      <description>Chhaya,&lt;BR /&gt;&lt;BR /&gt;I found these interesting messages in /var/log/messages:&lt;BR /&gt;&lt;BR /&gt;Dec  7 14:06:51 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "getattr" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 6bf2a6f9-223c-41e9-9921-1fe975979551&lt;BR /&gt;Dec  7 14:07:23 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "getattr" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 6bf2a6f9-223c-41e9-9921-1fe975979551&lt;BR /&gt;Dec  7 14:18:21 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "getattr" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 6bf2a6f9-223c-41e9-9921-1fe975979551&lt;BR /&gt;Dec  7 14:24:22 smarty dbus: avc:  received setenforce notice (enforcing=0)&lt;BR /&gt;Dec  7 14:24:22 smarty dbus: avc:  received setenforce notice (enforcing=0)&lt;BR /&gt;Dec  7 14:24:22 smarty dbus: Can't send to audit system: USER_AVC avc:  received setenforce notice (enforcing=0)#012: exe="?" sauid=81 hostname=? addr=? terminal=?&lt;BR /&gt;Dec  7 14:27:36 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "getattr" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 6bf2a6f9-223c-41e9-9921-1fe975979551&lt;BR /&gt;Dec  7 14:27:51 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "read" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 7dc6822e-3ea6-4a3d-8afe-3e93ba167dc5&lt;BR /&gt;Dec  7 14:27:51 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "read" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 7dc6822e-3ea6-4a3d-8afe-3e93ba167dc5&lt;BR /&gt;Dec  7 15:32:37 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "getattr" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 6bf2a6f9-223c-41e9-9921-1fe975979551&lt;BR /&gt;Dec  7 15:32:37 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "read" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 7dc6822e-3ea6-4a3d-8afe-3e93ba167dc5&lt;BR /&gt;Dec  7 15:32:37 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "read" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 7dc6822e-3ea6-4a3d-8afe-3e93ba167dc5&lt;BR /&gt;Dec  7 15:35:56 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "getattr" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 6bf2a6f9-223c-41e9-9921-1fe975979551&lt;BR /&gt;Dec  7 15:35:56 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "read" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 7dc6822e-3ea6-4a3d-8afe-3e93ba167dc5&lt;BR /&gt;Dec  7 15:35:56 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "read" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 7dc6822e-3ea6-4a3d-8afe-3e93ba167dc5&lt;BR /&gt;Dec  7 16:34:10 smarty dbus: avc:  received setenforce notice (enforcing=1)&lt;BR /&gt;Dec  7 16:34:10 smarty dbus: avc:  received setenforce notice (enforcing=1)&lt;BR /&gt;Dec  7 16:34:10 smarty dbus: Can't send to audit system: USER_AVC avc:  received setenforce notice (enforcing=1)#012: exe="?" sauid=81 hostname=? addr=? terminal=?&lt;BR /&gt;Dec  7 16:34:11 smarty dbus: [system] Reloaded configuration&lt;BR /&gt;Dec  7 16:35:37 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "getattr" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 6bf2a6f9-223c-41e9-9921-1fe975979551&lt;BR /&gt;Dec  7 16:36:06 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "getattr" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 6bf2a6f9-223c-41e9-9921-1fe975979551&lt;BR /&gt;Dec  7 16:38:10 smarty dbus: avc:  received setenforce notice (enforcing=0)&lt;BR /&gt;Dec  7 16:38:10 smarty dbus: avc:  received setenforce notice (enforcing=0)&lt;BR /&gt;Dec  7 16:38:10 smarty dbus: Can't send to audit system: USER_AVC avc:  received setenforce notice (enforcing=0)#012: exe="?" sauid=81 hostname=? addr=? terminal=?&lt;BR /&gt;Dec  7 16:38:26 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "getattr" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 6bf2a6f9-223c-41e9-9921-1fe975979551&lt;BR /&gt;Dec  7 16:38:26 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "read" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 7dc6822e-3ea6-4a3d-8afe-3e93ba167dc5&lt;BR /&gt;Dec  7 16:38:26 smarty setroubleshoot: SELinux is preventing /usr/sbin/httpd "read" access to /etc/pki/tls/private/localhost.key. For complete SELinux messages. run sealert -l 7dc6822e-3ea6-4a3d-8afe-3e93ba167dc5&lt;BR /&gt;&lt;BR /&gt;When I ran `setsebool -P httpd_disable_trans 1` I got:&lt;BR /&gt;&lt;BR /&gt;libsemanage.dbase_llist_set: record not found in the database (No such file or directory).&lt;BR /&gt;libsemanage.dbase_llist_set: could not set record value (No such file or directory).&lt;BR /&gt;Could not change boolean httpd_disable_trans&lt;BR /&gt;Could not change policy booleans&lt;BR /&gt;&lt;BR /&gt;I guess the value you mean has a different name in my installation?&lt;BR /&gt;&lt;BR /&gt;getsebool -a|grep httpd&lt;BR /&gt;allow_httpd_anon_write --&amp;gt; off&lt;BR /&gt;allow_httpd_mod_auth_ntlm_winbind --&amp;gt; off&lt;BR /&gt;allow_httpd_mod_auth_pam --&amp;gt; off&lt;BR /&gt;allow_httpd_sys_script_anon_write --&amp;gt; off&lt;BR /&gt;httpd_builtin_scripting --&amp;gt; on&lt;BR /&gt;httpd_can_network_connect --&amp;gt; off&lt;BR /&gt;httpd_can_network_connect_cobbler --&amp;gt; off&lt;BR /&gt;httpd_can_network_connect_db --&amp;gt; off&lt;BR /&gt;httpd_can_network_relay --&amp;gt; off&lt;BR /&gt;httpd_can_sendmail --&amp;gt; off&lt;BR /&gt;httpd_dbus_avahi --&amp;gt; on&lt;BR /&gt;httpd_enable_cgi --&amp;gt; on&lt;BR /&gt;httpd_enable_ftp_server --&amp;gt; off&lt;BR /&gt;httpd_enable_homedirs --&amp;gt; off&lt;BR /&gt;httpd_execmem --&amp;gt; off&lt;BR /&gt;httpd_read_user_content --&amp;gt; off&lt;BR /&gt;httpd_ssi_exec --&amp;gt; off&lt;BR /&gt;httpd_tmp_exec --&amp;gt; off&lt;BR /&gt;httpd_tty_comm --&amp;gt; on&lt;BR /&gt;httpd_unified --&amp;gt; off&lt;BR /&gt;httpd_use_cifs --&amp;gt; off&lt;BR /&gt;httpd_use_gpg --&amp;gt; off&lt;BR /&gt;httpd_use_nfs --&amp;gt; off&lt;BR /&gt;&lt;BR /&gt;sealert -l 6bf2a6f9-223c-41e9-9921-1fe975979551&lt;BR /&gt;&lt;BR /&gt;Summary:&lt;BR /&gt;&lt;BR /&gt;SELinux is preventing /usr/sbin/httpd "getattr" access to&lt;BR /&gt;/etc/pki/tls/private/localhost.key.&lt;BR /&gt;&lt;BR /&gt;Detailed Description:&lt;BR /&gt;&lt;BR /&gt;[SELinux is in permissive mode. This access was not denied.]&lt;BR /&gt;&lt;BR /&gt;SELinux denied access requested by httpd. /etc/pki/tls/private/localhost.key may&lt;BR /&gt;be a mislabeled. /etc/pki/tls/private/localhost.key default SELinux type is&lt;BR /&gt;cert_t, but its current type is admin_home_t. Changing this file back to the&lt;BR /&gt;default type, may fix your problem.&lt;BR /&gt;&lt;BR /&gt;File contexts can be assigned to a file in the following ways.&lt;BR /&gt;&lt;BR /&gt;  * Files created in a directory receive the file context of the parent&lt;BR /&gt;    directory by default.&lt;BR /&gt;  * The SELinux policy might override the default label inherited from the&lt;BR /&gt;    parent directory by specifying a process running in context A which creates&lt;BR /&gt;    a file in a directory labeled B will instead create the file with label C.&lt;BR /&gt;    An example of this would be the dhcp client running with the dhclient_t type&lt;BR /&gt;    and creating a file in the directory /etc. This file would normally receive&lt;BR /&gt;    the etc_t type due to parental inheritance but instead the file is labeled&lt;BR /&gt;    with the net_conf_t type because the SELinux policy specifies this.&lt;BR /&gt;  * Users can change the file context on a file using tools such as chcon, or&lt;BR /&gt;    restorecon.&lt;BR /&gt;&lt;BR /&gt;This file could have been mislabeled either by user error, or if an normally&lt;BR /&gt;confined application was run under the wrong domain.&lt;BR /&gt;&lt;BR /&gt;However, this might also indicate a bug in SELinux because the file should not&lt;BR /&gt;have been labeled with this type.&lt;BR /&gt;&lt;BR /&gt;If you believe this is a bug, please file a bug report against this package.&lt;BR /&gt;&lt;BR /&gt;Allowing Access:&lt;BR /&gt;&lt;BR /&gt;You can restore the default system context to this file by executing the&lt;BR /&gt;restorecon command. restorecon '/etc/pki/tls/private/localhost.key', if this&lt;BR /&gt;file is a directory, you can recursively restore using restorecon -R&lt;BR /&gt;'/etc/pki/tls/private/localhost.key'.&lt;BR /&gt;&lt;BR /&gt;Fix Command:&lt;BR /&gt;&lt;BR /&gt;/sbin/restorecon '/etc/pki/tls/private/localhost.key'&lt;BR /&gt;&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Source Context                unconfined_u:system_r:httpd_t:s0&lt;BR /&gt;Target Context                unconfined_u:object_r:admin_home_t:s0&lt;BR /&gt;Target Objects                /etc/pki/tls/private/localhost.key [ file ]&lt;BR /&gt;Source                        httpd&lt;BR /&gt;Source Path                   /usr/sbin/httpd&lt;BR /&gt;Port                          &lt;UNKNOWN&gt;&lt;BR /&gt;Host                          smarty.domain.com&lt;BR /&gt;Source RPM Packages           httpd-2.2.17-1.fc13.1&lt;BR /&gt;Target RPM Packages&lt;BR /&gt;Policy RPM                    selinux-policy-3.7.19-10.fc13&lt;BR /&gt;Selinux Enabled               True&lt;BR /&gt;Policy Type                   targeted&lt;BR /&gt;Enforcing Mode                Permissive&lt;BR /&gt;Plugin Name                   restorecon&lt;BR /&gt;Host Name                     smarty.domain.com&lt;BR /&gt;Platform                      Linux smarty.domain.com 2.6.33.3-85.fc13.x86_64 #1&lt;BR /&gt;                              SMP Thu May 6 18:09:49 UTC 2010 x86_64 x86_64&lt;BR /&gt;Alert Count                   9&lt;BR /&gt;First Seen                    Tue Dec  7 14:06:48 2010&lt;BR /&gt;Last Seen                     Tue Dec  7 16:38:24 2010&lt;BR /&gt;Local ID                      6bf2a6f9-223c-41e9-9921-1fe975979551&lt;BR /&gt;Line Numbers&lt;BR /&gt;&lt;BR /&gt;Raw Audit Messages&lt;BR /&gt;&lt;BR /&gt;node=smarty.domain.com type=AVC msg=audit(1291736304.119:3020): avc:  denied  { getattr } for  pid=3623 comm="httpd" path="/etc/pki/tls/private/localhost.key" dev=dm-4 ino=1179673 scontext=unconfined_u:system_r:httpd_t:s0 tcontext=unconfined_u:object_r:admin_home_t:s0 tclass=file&lt;BR /&gt;&lt;BR /&gt;node=smarty.domain.com type=SYSCALL msg=audit(1291736304.119:3020): arch=c000003e syscall=4 success=yes exit=0 a0=7f6c9e2e25a8 a1=7fff0fa02ab0 a2=7fff0fa02ab0 a3=1bb items=0 ppid=3622 pid=3623 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts7 ses=1 comm="httpd" exe="/usr/sbin/httpd" subj=unconfined_u:system_r:httpd_t:s0 key=(null)&lt;BR /&gt;&lt;BR /&gt;So I tried:&lt;BR /&gt;&lt;BR /&gt;/sbin/restorecon '/etc/pki/tls/private/localhost.key'&lt;BR /&gt;&lt;BR /&gt;and tried again. I will post again with more results.&lt;BR /&gt;&lt;BR /&gt;Christian&lt;/UNKNOWN&gt;</description>
      <pubDate>Wed, 08 Dec 2010 11:01:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722152#M70</guid>
      <dc:creator>Christian Deutsch_1</dc:creator>
      <dc:date>2010-12-08T11:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Apache startup failed (points!)</title>
      <link>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722153#M71</link>
      <description>After applying the restorecon fix commands (see my previous post) now I get the following messages in /var/log/messages:&lt;BR /&gt;&lt;BR /&gt;Dec  8 12:02:11 smarty dbus: avc:  received setenforce notice (enforcing=1)&lt;BR /&gt;Dec  8 12:02:11 smarty dbus: avc:  received setenforce notice (enforcing=1)&lt;BR /&gt;Dec  8 12:02:11 smarty dbus: Can't send to audit system: USER_AVC avc:  received setenforce notice (enforcing=1)#012: exe="?" sauid=81 hostname=? addr=? terminal=?&lt;BR /&gt;Dec  8 12:02:11 smarty dbus: [system] Reloaded configuration&lt;BR /&gt;Dec  8 12:04:23 smarty dbus: avc:  received setenforce notice (enforcing=0)&lt;BR /&gt;Dec  8 12:04:23 smarty dbus: avc:  received setenforce notice (enforcing=0)&lt;BR /&gt;Dec  8 12:04:23 smarty dbus: Can't send to audit system: USER_AVC avc:  received setenforce notice (enforcing=0)#012: exe="?" sauid=81 hostname=? addr=? terminal=?&lt;BR /&gt;Dec  8 12:05:37 smarty dbus: avc:  received setenforce notice (enforcing=1)&lt;BR /&gt;Dec  8 12:05:37 smarty dbus: avc:  received setenforce notice (enforcing=1)&lt;BR /&gt;Dec  8 12:05:37 smarty dbus: Can't send to audit system: USER_AVC avc:  received setenforce notice (enforcing=1)#012: exe="?" sauid=81 hostname=? addr=? terminal=?&lt;BR /&gt;Dec  8 12:05:37 smarty dbus: [system] Reloaded configuration&lt;BR /&gt;&lt;BR /&gt;Behaviour with SELinux is now:&lt;BR /&gt;&lt;BR /&gt;Enforced mode: web page is not served (0 bytes are served)&lt;BR /&gt;Permissive mode: everything is fine&lt;BR /&gt;&lt;BR /&gt;If you want me to try any more tweaks with SELinux you can give me some hints.&lt;BR /&gt;&lt;BR /&gt;Christian</description>
      <pubDate>Wed, 08 Dec 2010 11:21:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/linux-based-community-regional/apache-startup-failed-points/m-p/4722153#M71</guid>
      <dc:creator>Christian Deutsch_1</dc:creator>
      <dc:date>2010-12-08T11:21:45Z</dc:date>
    </item>
  </channel>
</rss>

