| Summary: | [RFE] Named resource agent should run named as the named user, not root. | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 6 | Reporter: | Colin.Simpson | |
| Component: | resource-agents | Assignee: | Chris Feist <cfeist> | |
| Status: | CLOSED WONTFIX | QA Contact: | Cluster QE <mspqa-list> | |
| Severity: | low | Docs Contact: | ||
| Priority: | medium | |||
| Version: | 6.0 | CC: | cluster-maint, djansa, lhh, rdassen | |
| Target Milestone: | rc | Keywords: | FutureFeature, Triaged | |
| Target Release: | --- | |||
| Hardware: | Unspecified | |||
| OS: | Unspecified | |||
| Whiteboard: | ||||
| Fixed In Version: | Doc Type: | Enhancement | ||
| Doc Text: | Story Points: | --- | ||
| Clone Of: | ||||
| : | 711586 (view as bug list) | Environment: | ||
| Last Closed: | 2011-06-24 20:34:05 UTC | Type: | --- | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Bug Depends On: | ||||
| Bug Blocks: | 693781, 711586, 987587 | |||
|
Description
Colin.Simpson
2011-02-27 13:56:02 UTC
(In reply to comment #0) > I have looked at Fedora 14's named resource agent and it doesn't seem to have > these features so this query maybe an upstream one. But I'm not sure what the > the upstream is for this? @Colin: resource agents are used in a variety of upstream distros, but if you're interested in getting this fixed upstream best place to file a bug would be Fedora against the resource-agents package. When Fedora has this fixed, we can look at pulling the fixes into RHEL. That's cool, I have added a Bug #680775 for Fedora to hopefully action. And I have opened a SR#428006 with support pointing at this bug report. Thanks Updating bz to refer to issue #1. Making sure the named daemon runs as the user "named" instead of root. Issue #2 has been moved to bz#711586. After digging deeper into getting the agent to run as named, there can potentially be issues if named has already been run as the root user. It's possible that some of the bind configuration files will not have the correct permissions which would break an upgrade. However, there is a simple workaround. Add the option 'named_options="-u named"' to the named service in your cluster.conf file and the service will be run as the user 'named'. Closing this as WONTFIX for now as an upgrade will likely break current installs, and there is a simple workaround. |