Bug 1995594
| Summary: | RFE: Grant rpc.gssd access to $HOME/.k5identity in selinux-policy [rhel-8.4.0.z] | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | RHEL Program Management Team <pgm-rhel-tools> |
| Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
| Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 8.5 | CC: | dwysocha, jshivers, lvrabec, mmalik, pkoncity, plautrba, ssekidde, steved, toneata, yoyang, zpytela |
| Target Milestone: | beta | Keywords: | FutureFeature, Triaged, ZStream |
| Target Release: | 8.4 | Flags: | pm-rhel:
mirror+
|
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | selinux-policy-3.14.3-67.el8_4.2 | Doc Type: | Enhancement |
| Doc Text: |
Feature:
Support in selinux-policy to allow rpc.gssd apply the rules from $HOME/.k5identity
Reason:
BZ#1995593 backports to RHEL 8.4 the rpc.gssd capability to scan for $HOME/.k5identity to know the preferred UPN when reading the user's DEFCKTNAME, but SELinux prevents access to $HOME and $HOME/.k5identity.
Result:
rpc.gssd has access to the required files so that it is manageable which Kerberos principals are used to access a given resource.
|
Story Points: | --- |
| Clone Of: | 1951093 | Environment: | |
| Last Closed: | 2021-09-21 08:49:23 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1951093 | ||
| Bug Blocks: | |||
|
Comment 17
errata-xmlrpc
2021-09-21 08:49:23 UTC
|