"sh: /conf/pfatt/bin/pfatt.sh: Permission denied" on pfSense 2.6 w/ ZFS #81
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: hhf/pfatt#81
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Not sure if this is an issue, or just something I’m doing wrong. I’m fairly new to pfSense and a lot of this is over my head.
I installed pfSense 2.6 on a Protectli Vault and selected ZFS for the filesystem. I followed the bridge method instructions from the supplicant branch, but couldn’t get it working, so I tried the master branch, and it worked fine. Then I decided try the supplicant method with certificates.
During bootup, I kept getting:
sh: /conf/pfatt/bin/pfatt.sh: Permission deniedMy file permissions, showed:
-rwxr-xr-x 1 root wheel 9194 Apr 5 14:18 pfatt.shSince I couldn’t get it working, I moved
pfatt.shto/root/binand left the certs in/conf/pfatt/wpa. I rebooted and everything worked as expected.There’s a Netgate forum post (see Apr 26, 2022, 6:03PM & Jul 21, 2022, 4:24 PM) which discusses a similar permissions issue. They mention
/confbeing locked down and a Netgate admin says to use/rootinstead. That led me to trymount -p, which shows:pfSense/cf/conf /cf/conf zfs rw,noexec,nosuid,noatime,nfsv4acls 0I’m assuming
noexecon thepfSense/cf/confline meanspfatt.shcan’t run in the/confdirectory. Does this sound correct? If so, any issue with leavingpfatt.shin/root/bin? Thanks.Correct
No issue, just make sure you have the correct path(s) when calling the script, certificates, etc.
Is there a particular reason why /conf was chosen as the folder for the pfatt.* scripts in the first place? I recall this being used way back - 3+ years ago when the script first came about.
Thanks!
To be honest I'm not familiar enough with pfSense to know.