Bug 1253619
Summary: | pam_timestamp cannot create timestamp file | |||
---|---|---|---|---|
Product: | Red Hat Enterprise Linux 6 | Reporter: | Dalibor Pospíšil <dapospis> | |
Component: | pam | Assignee: | Tomas Mraz <tmraz> | |
Status: | CLOSED WONTFIX | QA Contact: | BaseOS QE Security Team <qe-baseos-security> | |
Severity: | unspecified | Docs Contact: | ||
Priority: | unspecified | |||
Version: | 6.6 | CC: | dapospis, dwalsh, lvrabec, mgrepl, mmalik, pkis, plautrba, pvrabec, ssekidde | |
Target Milestone: | rc | |||
Target Release: | --- | |||
Hardware: | Unspecified | |||
OS: | Unspecified | |||
Whiteboard: | ||||
Fixed In Version: | Doc Type: | Bug Fix | ||
Doc Text: | Story Points: | --- | ||
Clone Of: | ||||
: | 1253632 (view as bug list) | Environment: | ||
Last Closed: | 2016-01-28 16:56:05 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: |
Description
Dalibor Pospíšil
2015-08-14 09:27:30 UTC
Shouldn't it be using /var/db/sudo directory? (In reply to Milos Malik from comment #1) > Shouldn't it be using /var/db/sudo directory? According to man page it should be /var/run/sudo/..., see man pam_timestamp We have type_transition sshd_t var_run_t : dir pam_var_run_t "sudo"; in RHEL-7. Unfortunatelly we don't have filename transitions rules in RHEL-6. We need to find a different way in RHEL-6. Development Management has reviewed and declined this request. You may appeal this decision by reopening this request. There is no way to fix it in selinux-policy? I think, it is fair to answer the question before clearing the needinfo flag. The reason I was asking is, to see if there is no other way to fix this issue other than it is fixed in RHEL-7. This is clearly a non functioning solution, and if possible, it should be addressed. The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days |