Bug 122030 - gpg doesn't have access to read files in ~/public_html
gpg doesn't have access to read files in ~/public_html
Product: Fedora
Classification: Fedora
Component: policy (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Russell Coker
Ben Levenson
Depends On:
  Show dependency treegraph
Reported: 2004-04-29 16:22 EDT by Gary Peck
Modified: 2007-11-30 17:10 EST (History)
1 user (show)

See Also:
Fixed In Version: 1.25.4-10.1
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2005-09-15 11:57:53 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Gary Peck 2004-04-29 16:22:32 EDT
Description of problem:
I was trying to sign a file in my public_html directory with gpg but
was getting permission denied errors. It seems that gpg should have
permission to pretty much every normal file under ${HOME}, as you
could potentially want to sign anything.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. gpg -ab /home/gary/public_html/elmer/foaf.rdf
2. Enter your secret key password
Actual results:
gpg: can't open foaf.rdf: Permission denied
gpg: signing failed: file open error

Expected results:
File gets signed successfully.

Additional info:
The following message was in /var/log/messages:

audit(1083266767.282:0): avc:  denied  { search } for  pid=8845
exe=/usr/bin/gpg name=elmer dev=dm-1 ino=117010
tcontext=system_u:object_r:httpd_user_content_t tclass=dir

$ ls -l /home/gary/public_html/elmer/foaf.rdf
-rw-r--r--  1 gary gary 3500 Apr 29 15:39
$ ls -Z /home/gary/public_html/elmer/foaf.rdf
-rw-r--r--+ gary     gary     user_u:object_r:httpd_user_content_t
$ ls -Zd /home/gary/public_html/elmer
drwxr-xr-x+ gary     gary     system_u:object_r:httpd_user_content_t
Comment 1 Daniel Walsh 2004-11-06 01:34:50 EST
Fixed in selinux-policy-strict-1.18.2-2

Note You need to log in before you can comment on or make changes to this bug.