Description of problem: after applying DISA STIG PCI-DSS audit rules on rhvh it is not possible to add this host to manager Version-Release number of selected component (if applicable): rhvh 4.1.6 and most probably versions before How reproducible: everytime Steps to Reproduce: 1. install rhvh 2. create thin lv for /tmp and mount it with "noexec" option 3. try to add host from manager Actual results: 2017-10-30 05:02:59,163-04 ERROR [org.ovirt.engine.core.bll.hostdeploy.VdsDeployBase] (VdsDeploy) [2986cfa7] Error during deploy dialog 2017-10-30 05:02:59,171-04 ERROR [org.ovirt.engine.core.bll.hostdeploy.VdsDeployBase] (org.ovirt.thread.pool-6-thread-7) [2986cfa7] Error during host 10.37.192.203 install 2017-10-30 05:02:59,211-04 ERROR [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector] (org.ovirt.thread.pool-6-thread-7) [2986cfa7] EVENT_ID: VDS_INSTALL_IN_PROGRESS_ERROR(511), Correlation ID: 2986cfa7, Call Stack: null, Custom ID: null, Custom Event ID: -1, Message: Failed to install Host noexechost. Unexpected error during execution: bash: /tmp/ovirt-nFmb9TnASj/ovirt-host-deploy: Permission denied Expected results: host will be added Additional info: is it possible to make host compliant and move the deploy scritps to different location?
This should also be reproducible on RHEL hosts. ovirt-host-deploy uses /tmp on both variants. Changing component.
Moving to infra team for review. Martin, what do you think?
Targeting to 4.3 as it's planned to evaluate those security standards during 4.3 planning
sync2jira
Moving to MODIFIED as ansible is using /root directory to store temporary data including executed scripts
Verified on ovirt-engine-4.4.0-0.32.master.el8ev.noarch Machine with noexec /tmp (and /home) can be added as a host.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Important: RHV Manager (ovirt-engine) 4.4 security, bug fix, and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2020:3247