Bug 860221
| Summary: | haproxy needs static uid/gid assignment | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 6 | Reporter: | Ryan O'Hara <rohara> |
| Component: | setup | Assignee: | Ondrej Vasik <ovasik> |
| Status: | CLOSED ERRATA | QA Contact: | qe-baseos-daemons |
| Severity: | low | Docs Contact: | |
| Priority: | medium | ||
| Version: | 6.4 | CC: | asersen, azelinka, rohara |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | setup-2.8.14-19.el6 | Doc Type: | Bug Fix |
| Doc Text: |
Cause:
haproxy is network load balancer and creates system user account haproxy. This account was created with dynamic assigned uid/gid.
Consequence:
Dynamic uid/gid assignment is not recommended for network daemons.
Fix:
Uid/gid pair 188:188 was reserved by setup package.
Result:
Haproxy package could create user haproxy with this static uid/gid.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2012-10-15 09:06:58 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Ryan O'Hara
2012-09-25 09:53:09 UTC
This request was evaluated by Red Hat Product Management for inclusion in the current release of Red Hat Enterprise Linux. Because the affected component is not scheduled to be updated in the current release, Red Hat is unable to address this request at this time. Red Hat invites you to ask your support representative to propose this request, if appropriate, in the next release of Red Hat Enterprise Linux. Just one question - which package creates the user/group haproxy? Btw. you should have the static uid assignment only if the user/group owns/stores sensitive data or communicates via network/virtual machines. Otherwise is perfectly fine to have dynamic assignment. Given the fact that the username contains word proxy, I expect static would be better in this case. (In reply to comment #5) > Just one question - which package creates the user/group haproxy? > Btw. you should have the static uid assignment only if the user/group > owns/stores sensitive data or communicates via network/virtual machines. > Otherwise is perfectly fine to have dynamic assignment. Given the fact that > the username contains word proxy, I expect static would be better in this > case. The haproxy package creates the haproxy user/group. You are correct in assuming that haproxy communicates over a network -- haproxy is a network load balancer. Thanks. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2012-1367.html |