Bug 1466949

Summary: esc created .redhat directory fails STIG umask check
Product: Red Hat Enterprise Linux 7 Reporter: David Sirrine <dsirrine>
Component: escAssignee: Jack Magne <jmagne>
Status: CLOSED ERRATA QA Contact: Asha Akkiangady <aakkiang>
Severity: high Docs Contact:
Priority: high    
Version: 7.3CC: jhunt, jmagne, lmiksik, mharmsen, nkinder, rpattath
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: All   
Whiteboard:
Fixed In Version: esc-1.1.0-39.el7 Doc Type: Bug Fix
Doc Text:
Installing this update will assure that esc will, upon istallation, maintain all of its files and directories at the proper permissions level, to avoid any possible unauthorized access.
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-04-10 18:16:55 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description David Sirrine 2017-06-30 20:35:32 UTC
Description of problem:
STIG requires umask of 077. ESC creates .redhat profile directory with chmod of 755. This causes a failed STIG validation.

Version-Release number of selected component (if applicable):
esc-1.1.0-37

How reproducible:
Always

Steps to Reproduce:
1. Install ESC
2. Set profile umask to 077
3. Run ESC

Actual results:
/home/$USER/.redhat has mode of 755

Expected results:
/home/$USER/.redhat has mode of 700

Comment 7 Roshni 2017-12-12 17:14:45 UTC
On a fresh installation I see the following which matches the output in your test instruction:

[rpattath@rpattath ~]$ rpm -q esc
esc-1.1.0-38.el7.x86_64
[rpattath@rpattath ~]$ cd /home/rpattath/
[rpattath@rpattath ~]$ ls -la | grep .redhat
drwx------.  3 rpattath rpattath 4096 Dec 11 15:55 .redhat

Comment 9 Matthew Harmsen 2018-01-08 19:16:13 UTC
Moving bug back to ASSIGNED to address this issue.

Comment 13 Roshni 2018-01-11 20:57:24 UTC
[root@dhcp129-107 ~]# rpm -qi esc
Name        : esc
Version     : 1.1.0
Release     : 39.el7
Architecture: x86_64
Install Date: Thu 11 Jan 2018 03:44:58 PM EST
Group       : Applications/Internet
Size        : 1379872
License     : GPL+
Signature   : (none)
Source RPM  : esc-1.1.0-39.el7.src.rpm
Build Date  : Tue 09 Jan 2018 07:07:45 PM EST
Build Host  : x86-041.build.eng.bos.redhat.com
Relocations : (not relocatable)
Packager    : Red Hat, Inc. <http://bugzilla.redhat.com/bugzilla>
Vendor      : Red Hat, Inc.
URL         : http://directory.fedoraproject.org/wiki/CoolKey
Summary     : Enterprise Security Client Smart Card Client

Not seeing the issue in comment 5.

Comment 16 errata-xmlrpc 2018-04-10 18:16:55 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:0975