Bug 138631 - /sbin/service breaks openldap/tls configuration for at least smbd
/sbin/service breaks openldap/tls configuration for at least smbd
Status: CLOSED WONTFIX
Product: Fedora
Classification: Fedora
Component: initscripts (Show other bugs)
3
All Linux
medium Severity medium
: ---
: ---
Assigned To: Bill Nottingham
Brock Organ
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2004-11-10 07:43 EST by Kristian Rietveld
Modified: 2014-03-16 22:50 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2004-11-10 12:38:34 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
proposed fix. (1.36 KB, patch)
2004-11-10 07:45 EST, Kristian Rietveld
no flags Details | Diff

  None (edit)
Description Kristian Rietveld 2004-11-10 07:43:21 EST
When configuring openldap clients to use TLS with certificates, the
paths to the cert and the key have to be saved in $HOME/.ldaprc. The
samba daemon can be configured to use ldap with TLS, and thus needs
access to $HOME/.ldaprc when setting up the connection. If you start
up smb using /sbin/service $HOME does not get set in the newly created
environment. This avoids smbd from getting the paths to its required 
certs/keys and thus from functioning properly.

Proposal is to also export $HOME in the newly created environment in
/sbin/service. [I am not sure if this introduces additional security
problems.]

The attached patch fixes this problem, this has been verified locally.
Comment 1 Kristian Rietveld 2004-11-10 07:45:08 EST
Created attachment 106407 [details]
proposed fix.
Comment 2 Bill Nottingham 2004-11-10 12:38:34 EST
It's really better for initscripts in general to not inherit the
environment; that's why this change was made.

This is probably something better handled specifcally in initscripts
that need a $HOME.

Note You need to log in before you can comment on or make changes to this bug.