Bug 1303176

Summary: Installation/configuration limited to non-root users for auditing purposes
Product: Red Hat Enterprise Linux 7 Reporter: Matthew Harmsen <mharmsen>
Component: pki-coreAssignee: Matthew Harmsen <mharmsen>
Status: CLOSED NOTABUG QA Contact: Asha Akkiangady <aakkiang>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 7.3CC: arubin, nkinder
Target Milestone: rc   
Target Release: 7.3   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-06-15 18:09:49 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Matthew Harmsen 2016-01-29 18:46:22 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/pki/ticket/1483

 For auditing purposes, what I'd expect the installation to work (and what should be tested) is for a non-root user to be able to run pkispawn and install successfully.  After installation completion, only the installation user has access to his/her admin pkcs12.
Same with starting/restarting the server.

It could be just some sudo configuration that narrow down sudo so that some are allowed only to install/start/restart pki servers, and then another to edit pki instance configurations.

Comment 2 Nathan Kinder 2016-06-15 18:09:49 UTC
There is really nothing to fix here.  Installation of RHCS requires root permission (direct or via sudo).  Using sudo should work just fine, but that is a procedural/system issue and not a code issue that requires a bug.