Bug 1541472 - FreeIPA with KRA (Password Vault) should allow /var/log/pki/pki-tomcat/kra/system
Summary: FreeIPA with KRA (Password Vault) should allow /var/log/pki/pki-tomcat/kra/sy...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: rkhunter
Version: 27
Hardware: x86_64
OS: Linux
unspecified
unspecified
Target Milestone: ---
Assignee: Kevin Fenzi
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-02-02 16:40 UTC by Anthony Messina
Modified: 2018-03-20 17:06 UTC (History)
3 users (show)

Fixed In Version: rkhunter-1.4.6-1.fc27 rkhunter-1.4.6-1.fc26 rkhunter-1.4.6-1.el7 rkhunter-1.4.6-1.el6
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-02-27 17:25:27 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Anthony Messina 2018-02-02 16:40:24 UTC
When using FreeIPA with KRA (Password Vault), the following should be allowed by default, just as are done for the CA (Certificate authority): Bug 849251, Bug 994567.  Note, just the paths are different.

# Already allowed for CA
EXISTWHITELIST=/var/log/pki/pki-tomcat/ca/system
RTKT_FILE_WHITELIST=/var/log/pki/pki-tomcat/ca/system

# Please allow for KRA
EXISTWHITELIST=/var/log/pki/pki-tomcat/kra/system
RTKT_FILE_WHITELIST=/var/log/pki/pki-tomcat/kra/system

For reference, the associated rkhunter warning:

Warning: The following processes are using suspicious files:
         Command: java
           UID: 17    PID: 5292
           Pathname: /var/log/pki/pki-tomcat/kra/system
           Possible Rootkit: Unknown rootkit

Comment 1 Fedora Update System 2018-02-26 00:06:02 UTC
rkhunter-1.4.6-1.el6 has been submitted as an update to Fedora EPEL 6. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-61b83e1b50

Comment 2 Fedora Update System 2018-02-26 00:06:19 UTC
rkhunter-1.4.6-1.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2018-ca69db5fee

Comment 3 Fedora Update System 2018-02-26 00:06:31 UTC
rkhunter-1.4.6-1.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2018-1d006205b5

Comment 4 Fedora Update System 2018-02-26 00:06:43 UTC
rkhunter-1.4.6-1.el7 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-a4f94f474c

Comment 5 Fedora Update System 2018-02-26 17:32:06 UTC
rkhunter-1.4.6-1.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-1d006205b5

Comment 6 Fedora Update System 2018-02-26 18:06:36 UTC
rkhunter-1.4.6-1.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-ca69db5fee

Comment 7 Fedora Update System 2018-02-26 18:08:47 UTC
rkhunter-1.4.6-1.el7 has been pushed to the Fedora EPEL 7 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-a4f94f474c

Comment 8 Fedora Update System 2018-02-26 18:11:21 UTC
rkhunter-1.4.6-1.el6 has been pushed to the Fedora EPEL 6 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-61b83e1b50

Comment 9 Fedora Update System 2018-02-27 17:25:27 UTC
rkhunter-1.4.6-1.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.

Comment 10 Fedora Update System 2018-03-06 17:30:55 UTC
rkhunter-1.4.6-1.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2018-03-20 17:03:57 UTC
rkhunter-1.4.6-1.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2018-03-20 17:06:20 UTC
rkhunter-1.4.6-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.