Bug 2168961
| Summary: | selinux-policy AVC denials during ipa trust-add [rhel-9.1.0.z] | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | Reporter: | RHEL Program Management Team <pgm-rhel-tools> |
| Component: | selinux-policy | Assignee: | Nikola Knazekova <nknazeko> |
| Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 9.1 | CC: | frenaud, lvrabec, mmalik, nknazeko, rcritten, ssekidde, tscherf, zpytela |
| Target Milestone: | rc | Keywords: | Reopened, Triaged, ZStream |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | selinux-policy-34.1.43-1.el9_1.2 | Doc Type: | If docs needed, set a value |
| Doc Text: |
Cause: Missing permission leads to selinux-policy AVC denials during ipa trust-add
Consequence: this issue prevents using the trust feature in selinux enforcing mode. This feature is important to many IdM customers and RHEL 9.1 is the most recent version available on RHEL 9.
Fix: Allow smbd_t process noatsecure permission for winbind_rpcd_t
Result: No AVC denials
|
Story Points: | --- |
| Clone Of: | 2114902 | Environment: | |
| Last Closed: | 2023-02-28 08:21:20 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2114902 | ||
| Bug Blocks: | |||
|
Comment 8
errata-xmlrpc
2023-02-28 08:21:20 UTC
|