【问题标题】:ansible.posix.firewalld fails with Polkit erroransible.posix.firewalld 因 Polkit 错误而失败
【发布时间】:2021-10-24 15:19:35
【问题描述】:

这可能是一个简单的解决方法,但我的 google-fu 找不到任何东西。也许拉错了错误的部分......无论如何,尝试为入站http设置一个简单的防火墙规则。

这看起来像是become 的某种权限问题?

我已将 SELinux 设置为 permissive,但发现此问题仍然存在,因此我认为它与 SELinux 无关。

服务器

所有系统都运行完全更新的 Fedora 34。所有机器也都安装了python3-firewall包。

  1. 主 FreeIPA 服务器,(10.1.0.11)
  2. 辅助 FreeIAP 服务器 (10.1.0.12)
  3. Ansible 服务器 (10.1.0.22)

正在尝试运行...

[brandonyoung@ansible01 ansible-lab01]$ ansible-playbook -K -i hosts.yml playbooks/testFirewalld.yml
BECOME password:

PLAY [IPAServers] *****************************************************************************

TASK [Gathering Facts] ************************************************************************
ok: [10.1.0.12]
ok: [10.1.0.11]

TASK [Ensure that HTTP is allowed through the firewall] ***************************************
ERROR:dbus.proxies:Introspect error on :1.6:/org/fedoraproject/FirewallD1: dbus.exceptions.DBusException: org.fedoraproject.slip.dbus.service.PolKit.NotAuthorizedException.org.fedoraproject.FirewallD1.info:
An exception occurred during task execution. To see the full traceback, use -vvv. The error was: dbus.exceptions.DBusException: org.fedoraproject.slip.dbus.service.PolKit.NotAuthorizedException.org.fedoraproject.FirewallD1.info:
fatal: [10.1.0.11]: FAILED! => {"msg": "Unexpected failure during module execution.", "stdout": ""}
ERROR:dbus.proxies:Introspect error on :1.6:/org/fedoraproject/FirewallD1: dbus.exceptions.DBusException: org.fedoraproject.slip.dbus.service.PolKit.NotAuthorizedException.org.fedoraproject.FirewallD1.info:
An exception occurred during task execution. To see the full traceback, use -vvv. The error was: dbus.exceptions.DBusException: org.fedoraproject.slip.dbus.service.PolKit.NotAuthorizedException.org.fedoraproject.FirewallD1.info:
fatal: [10.1.0.12]: FAILED! => {"msg": "Unexpected failure during module execution.", "stdout": ""}

PLAY RECAP ************************************************************************************
10.1.0.11                  : ok=1    changed=0    unreachable=0    failed=1    skipped=0    rescued=0    ignored=0
10.1.0.12                  : ok=1    changed=0    unreachable=0    failed=1    skipped=0    rescued=0    ignored=0

配置

hosts.yml

unitedStates:
  children:
    city:
      children:
        ansibleServers:
          hosts:
            10.1.0.22:
        IPAServers:
          hosts:
            10.1.0.11:
            10.1.0.12:
  vars:
    ntp_server: time.nist.gov
    ansible_python_interpreter: /usr/bin/python3

剧本/testFirewalld.yml

---
# This playbook will test some basic firewall rule enforcement using `ansible.posix.firewalld`

- hosts: IPAServers
  tasks:
    - name: Ensure that HTTP is allowed through the firewall
      ansible.posix.firewalld:
        service: http
        immediate: yes
        permanent: yes
        state: enabled
      become: yes

ansible-playbook -K -i hosts.yml playbooks/testFirewalld.yml -vvv 的输出:https://pastebin.com/ceskr5wJ

【问题讨论】:

    标签: ansible firewalld


    【解决方案1】:

    Firewalld 通常附带策略包定义。也许你的丢失或改变了。 AFAICS,firewalld polkit 通信正在发生。

    # ls -al /usr/share/polkit-1/actions/org.fedoraproject.FirewallD1.policy 
    lrwxrwxrwx. 1 root root 49 Jul 30 10:31 /usr/share/polkit-1/actions/org.fedoraproject.FirewallD1.policy -> org.fedoraproject.FirewallD1.server.policy.choice
    

    库存配置默认打开相关界面。

    # cat /usr/share/polkit-1/actions/org.fedoraproject.FirewallD1.server.policy.choice 
    [..]
      <action id="org.fedoraproject.FirewallD1.info">
        <description>General firewall information</description>
        <message>System policy prevents getting general firewall information</message>
        <defaults> 
          <allow_any>yes</allow_any>
          <allow_inactive>yes</allow_inactive>
          <allow_active>yes</allow_active>                                                 
        </defaults>                                                                        
      </action>                                                                            
    [..]
    

    您应该检查以确保您没有其他可能导致请求被拒绝的 polkit 规则。这些可能由您的发行版或管理员提供。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2014-08-09
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2022-08-11
      • 2016-08-15
      • 2016-06-13
      相关资源
      最近更新 更多