Bug 1413685

Summary: [SELinux] Director system is in permissive mode
Product: Red Hat Quickstart Cloud Installer Reporter: Thom Carlin <tcarlin>
Component: fusor-installerAssignee: Jason Montleon <jmontleo>
Status: CLOSED ERRATA QA Contact: Tasos Papaioannou <tpapaioa>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 1.1CC: jmontleo, qci-bugzillas, tpapaioa
Target Milestone: ---   
Target Release: 1.1   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-02-28 01:44:20 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Thom Carlin 2017-01-16 16:39:06 UTC
Description of problem:

After fusor-undercloud-installer runs, director system is in permissive mode

Version-Release number of selected component (if applicable):

1.1.0-1.el7

How reproducible:

100%

Steps to Reproduce:
1. Follow QCI TripleO installation steps up to running "fusor-undercloud-installer" [inclusive]
2. getenforce
3.

Actual results:

Permissive

Expected results:

Enforcing

Additional info:

This is done in /opt/theforeman/tfm/root/usr/share/gems/gems/egon-1.1.9/lib/egon/undercloud/commands.rb

File comes from tfm-rubygem-egon-1.1.9-1.el7sat in latest qciooo repo

Vanilla RHOSP 10 has SELinux in enforcing mode

Comment 2 Jason Montleon 2017-01-16 17:52:21 UTC
https://github.com/fusor/egon/pull/93

Comment 4 Tasos Papaioannou 2017-01-20 21:16:54 UTC
Verified on QCIOOO-10.0-RHEL-7-20170119.t.0.

Comment 6 errata-xmlrpc 2017-02-28 01:44:20 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2017:0335