Bug 2189268

Summary: auth_openidc.conf probably should be mode 0640 by default
Product: Red Hat Enterprise Linux 9 Reporter: Tomas Halman <thalman>
Component: mod_auth_openidcAssignee: Tomas Halman <thalman>
Status: CLOSED ERRATA QA Contact: Scott Poore <spoore>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 9.0CC: aboscatt, spoore
Target Milestone: rcKeywords: Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: mod_auth_openidc-2.4.9.4-4.el9 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-11-07 08:26:28 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Tomas Halman 2023-04-24 15:22:23 UTC
This bug was initially created as a copy of Bug #2141850

I am copying this bug because: 



Description of problem:

auth_openidc.conf can contain secrets.  It probably should be mode 0640 by default.

Version-Release number of selected component (if applicable):
mod_auth_openidc-2.3.7-11.module_el8.6.0+2868+44838709.x86_64

BTW - very happy to see this module in RHEL - thank you for providing it.

Comment 5 Scott Poore 2023-05-11 19:05:35 UTC
Verified.

Version ::

mod_auth_openidc-2.4.9.4-4.el9.x86_64


Results ::

Gating tests run:

-------------------- generated xml file: /root/federation_testing/result_oidc.xml ---------------------
========================================== 4 passed in 1.60s ==========================================

[root ~/federation_testing]# ls -l /etc/httpd/conf.d/auth_openidc.conf 
-rw-r-----. 1 root apache 57516 Apr 24 16:03 /etc/httpd/conf.d/auth_openidc.conf

Comment 7 errata-xmlrpc 2023-11-07 08:26:28 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: mod_auth_openidc security and bug fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2023:6365