Bug 2112372
Summary: | sudoing as sysadm_r still requires specifying "-r sysadm_r" parameter | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | Reporter: | Patrik Koncity <pkoncity> |
Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
Status: | CLOSED NOTABUG | QA Contact: | BaseOS QE Security Team <qe-baseos-security> |
Severity: | medium | Docs Contact: | |
Priority: | low | ||
Version: | 8.3 | CC: | lvrabec, mmalik, ssekidde |
Target Milestone: | rc | Keywords: | Triaged |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | No Doc Update | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2023-02-02 16:44:28 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Patrik Koncity
2022-07-29 14:12:23 UTC
After evaluating available resources, I am going to close also this bz unless some additional argument appears. The recommended confined administrators setup is described in the "Confining an administrator using sudo and the sysadm_r role" chapter in the product documentation, Using SELinux: https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/using_selinux/managing-confined-and-unconfined-users_using-selinux#confining-an-administrator-using-sudo-and-the-sysadm_r-role_managing-confined-and-unconfined-users or for particular domains administrators (e. g. webadm_r): https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html-single/using_selinux/index#selinux-user-capabilities_managing-confined-and-unconfined-users The policy only contains a limited subset of commands where there is an automated transition when sysadm_r role is used for a non-root user that subsequently uses sudo to get the root privileges. See the attached kbase for workarounds. Closing the bz, see #c1 for the reasoning. |