Back to bug 2223764

Who When What Removed Added
Red Hat Bugzilla 2023-07-18 19:36:11 UTC Pool ID sst_system_roles_rhel_9
RHEL Program Management 2023-07-18 19:36:22 UTC Keywords Triaged
Red Hat One Jira (issues.redhat.com) 2023-07-18 19:37:13 UTC Link ID Red Hat Issue Tracker RHELPLAN-162662
Rich Megginson 2023-07-18 20:12:29 UTC Status NEW ASSIGNED
Link ID Github linux-system-roles/firewall/pull/159
Doc Type If docs needed, set a value Bug Fix
Target Release --- 9.3
Rich Megginson 2023-07-21 18:48:03 UTC Status ASSIGNED POST
Rich Megginson 2023-07-21 18:51:16 UTC Blocks 2224648
Rich Megginson 2023-07-21 19:09:31 UTC CC djez, jharuda, vdanek
Flags needinfo?(djez) needinfo?(jharuda) needinfo?(vdanek)
Jakub Haruda 2023-07-24 14:29:19 UTC Flags needinfo?(jharuda)
QA Contact rhel-cs-system-management-subsystem-qe jharuda
Rich Megginson 2023-08-02 14:42:38 UTC Fixed In Version rhel-system-roles-1.22.0-0.19.el9
Status POST MODIFIED
errata-xmlrpc 2023-08-02 15:02:45 UTC Status MODIFIED ON_QA
Rich Megginson 2023-08-10 13:38:25 UTC Doc Text Enhancement:
Make resetting to defaults reload instead of restart firewalld
Reason:
Reloading in firewalld should successfully complete the configuration reset, and restarting adds downtime which can be used to open a connection that persists after firewalld has finishes restarting; this connection can be used to bypass firewall rules, since firewalld will not block traffic from active connections.
Result:
Minimal downtime when using `previous: replaced`
Addresses an issue brought up in #140, where due to the restart on resetting to defaults, the feature may not be suitable for production environments.
Rich Megginson 2023-08-10 14:21:01 UTC Doc Type Bug Fix Enhancement
Jakub Haruda 2023-08-14 08:33:37 UTC Status ON_QA VERIFIED
Doc Text Enhancement:
Make resetting to defaults reload instead of restart firewalld
Reason:
Reloading in firewalld should successfully complete the configuration reset, and restarting adds downtime which can be used to open a connection that persists after firewalld has finishes restarting; this connection can be used to bypass firewall rules, since firewalld will not block traffic from active connections.
Result:
Minimal downtime when using `previous: replaced`
Addresses an issue brought up in #140, where due to the restart on resetting to defaults, the feature may not be suitable for production environments.
Cause:

Consequence:

Fix:

Result:

Back to bug 2223764