Bug 1885126

Summary: Nightly failure (enforcing mode) in test_acme.py::TestACME::test_mod_md
Product: [Fedora] Fedora Reporter: Petr Čech <pcech>
Component: freeipaAssignee: IPA Maintainers <ipa-maint>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: high    
Version: 32CC: abokovoy, fdc, ftrivino, ipa-maint, jcholast, jhrozek, mhjacks, pvoborni, rcritten, ssorce, tscherf, twoerner
Target Milestone: ---Keywords: Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: freeipa-4.9.3-1.fc34 freeipa-4.9.3-1.fc32 freeipa-4.9.3-1.fc33 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-04-02 00:17:43 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Petr Čech 2020-10-05 07:28:56 UTC
Cloned from upstream: https://pagure.io/freeipa/issue/8514

### Issue
The nightly test `test_acme.py::TestACME::test_mod_md` is failing in enforcing mode on master + fedora 32, see PR #[422](https://github.com/freeipa-pr-ci2/freeipa/pull/422).

The [report](http://freeipa-org-pr-ci.s3-website.eu-central-1.amazonaws.com/jobs/c7da53d8-fc2a-11ea-b1bc-fa163ee0e2d4/report.html) and [logs](http://freeipa-org-pr-ci.s3-website.eu-central-1.amazonaws.com/jobs/c7da53d8-fc2a-11ea-b1bc-fa163ee0e2d4/test_integration-test_acme.py-TestACME-test_mod_md/) show AVCs on the client binding to port 443:
```
avc:  denied  { name_connect } for  pid=20605 comm="httpd" dest=443 scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:http_port_t:s0 tclass=tcp_socket permissive=0
```

Comment 3 Rob Crittenden 2020-11-20 19:32:04 UTC
Upstream ticket:
https://pagure.io/freeipa/issue/8514

Comment 4 Rob Crittenden 2020-11-30 22:52:45 UTC
Upstream PR https://github.com/freeipa/freeipa/pull/5306

Comment 5 Rob Crittenden 2020-12-04 00:50:22 UTC
Fixed upstream
master:
https://pagure.io/freeipa/c/df4380c11fa7d8eb08a43bca41fad741c116ad65

Comment 6 Fedora Update System 2021-03-31 07:18:18 UTC
FEDORA-2021-04b050e3d1 has been submitted as an update to Fedora 34. https://bodhi.fedoraproject.org/updates/FEDORA-2021-04b050e3d1

Comment 7 Fedora Update System 2021-03-31 07:19:35 UTC
FEDORA-2021-b6f97d3eed has been submitted as an update to Fedora 33. https://bodhi.fedoraproject.org/updates/FEDORA-2021-b6f97d3eed

Comment 8 Fedora Update System 2021-03-31 07:20:44 UTC
FEDORA-2021-5679e54fda has been submitted as an update to Fedora 32. https://bodhi.fedoraproject.org/updates/FEDORA-2021-5679e54fda

Comment 9 Fedora Update System 2021-04-01 02:04:00 UTC
FEDORA-2021-04b050e3d1 has been pushed to the Fedora 34 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-04b050e3d1`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-04b050e3d1

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 10 Fedora Update System 2021-04-01 02:35:51 UTC
FEDORA-2021-b6f97d3eed has been pushed to the Fedora 33 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-b6f97d3eed`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-b6f97d3eed

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 11 Fedora Update System 2021-04-01 02:36:47 UTC
FEDORA-2021-5679e54fda has been pushed to the Fedora 32 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-5679e54fda`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-5679e54fda

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 12 Fedora Update System 2021-04-02 00:17:43 UTC
FEDORA-2021-04b050e3d1 has been pushed to the Fedora 34 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 13 Fedora Update System 2021-04-08 20:42:35 UTC
FEDORA-2021-5679e54fda has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 14 Fedora Update System 2021-04-08 20:56:57 UTC
FEDORA-2021-b6f97d3eed has been pushed to the Fedora 33 stable repository.
If problem still persists, please make note of it in this bug report.