Back to bug 1038281

Who When What Removed Added
RHEL Program Management 2013-12-04 19:48:31 UTC Target Release --- 4.0
Perry Myers 2013-12-05 19:08:13 UTC Priority unspecified high
CC pmyers
Target Milestone --- rc
Severity medium high
Jason Guiditta 2013-12-05 20:05:34 UTC Status NEW ASSIGNED
Jason Guiditta 2013-12-05 21:24:48 UTC Status ASSIGNED POST
Lon Hohberger 2013-12-09 20:14:04 UTC Keywords Rebase
Red Hat Bugzilla 2013-12-09 20:14:04 UTC Doc Type Bug Fix Rebase: Bug Fixes and Enhancements
Lon Hohberger 2013-12-09 20:14:32 UTC Status POST MODIFIED
Fixed In Version openstack-foreman-installer-0.0.24-1.el6ost
yeylon 2013-12-10 21:15:10 UTC Keywords OtherQA
QA Contact ajeain ohochman
errata-xmlrpc 2013-12-11 21:17:24 UTC Status MODIFIED ON_QA
Bruce Reeler 2013-12-12 02:03:41 UTC CC breeler, jguiditt
Flags needinfo?(jguiditt)
Omri Hochman 2013-12-16 15:54:48 UTC Status ON_QA VERIFIED
Jason Guiditta 2013-12-17 19:39:37 UTC Doc Text Cause: Previously selinux was explicitly disabled by the openstack-foreman-installer.

Consequence: This poses a security risk, as selinux is disabled, even if the user previously had it enabled

Fix: Stop disabling it. Foreman itself will install the appropriate policy if the user has selinux enabled

Result: If the user had chosen to use selinux, the propoer policies will be installed. If they have it disabled, nothing will happen
Doc Type Rebase: Bug Fixes and Enhancements Bug Fix
Flags needinfo?(jguiditt)
Don Domingo 2013-12-17 23:51:56 UTC CC ddomingo
Doc Text Cause: Previously selinux was explicitly disabled by the openstack-foreman-installer.

Consequence: This poses a security risk, as selinux is disabled, even if the user previously had it enabled

Fix: Stop disabling it. Foreman itself will install the appropriate policy if the user has selinux enabled

Result: If the user had chosen to use selinux, the propoer policies will be installed. If they have it disabled, nothing will happen
Previously, the foreman_server.sh script contained a command that explicitly disabled SELinux. This posed a security risk, as the command disabled SELinux even if the user had it enabled previously.

This update removes the command that disables SELinux. As a result, Foreman now installs the appropriate policy if the user already has SELinux enabled.
errata-xmlrpc 2013-12-19 17:43:37 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2013-12-20 00:41:08 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2013-12-19 19:41:08 UTC
Perry Myers 2016-04-26 14:40:41 UTC CC pmyers

Back to bug 1038281