Bug 828369

Summary: katello.conf owned by katello:katello
Product: Red Hat Satellite Reporter: james labocki <jlabocki>
Component: InstallationAssignee: Lukas Zapletal <lzap>
Status: CLOSED UPSTREAM QA Contact: Katello QA List <katello-qa-list>
Severity: low Docs Contact:
Priority: unspecified    
Version: 6.0.0   
Target Milestone: Unspecified   
Target Release: Unused   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-08-03 09:41:30 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description james labocki 2012-06-04 17:25:12 UTC
/etc/httpd/conf.d/katello.conf is owned by katello:katello - Does it have to be this way? 

Having an application own the http config file is not best security practice and will create security audit alerts with enterprise customers.

Comment 1 Lukas Zapletal 2012-06-13 07:57:28 UTC
And what you recommend? It containst sensitive data (passwords) and it is read by katello user.

Comment 2 Lukas Zapletal 2012-08-03 09:35:26 UTC
Finally taking this one. Yeah, this particular config file does not contain any passwords. Will look into it.

Comment 3 Lukas Zapletal 2012-08-03 09:41:30 UTC
https://github.com/Katello/katello/pull/427