Bug 484713 - /usr/sbin/rhn-satellite restart not needed in /etc/sudoers
/usr/sbin/rhn-satellite restart not needed in /etc/sudoers
Status: CLOSED CURRENTRELEASE
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Server (Show other bugs)
530
All Linux
low Severity medium
: ---
: ---
Assigned To: Miroslav Suchý
wes hayutin
:
Depends On:
Blocks: 457079
  Show dependency treegraph
 
Reported: 2009-02-09 11:30 EST by Jan Pazdziora
Modified: 2009-09-10 15:11 EDT (History)
3 users (show)

See Also:
Fixed In Version: sat530
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2009-09-10 15:11:48 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Jan Pazdziora 2009-02-09 11:30:26 EST
Description of problem:

The default installation of Satellite 5.3.0 adds /usr/sbin/rhn-satellite restart to alias INSTALL_RHN in /etc/sudoers.

I've grepped Spacewalk source and /usr/sbin/rhn-satellite appears to be called in three places -- in spacewalk/setup/bin/spacewalk-setup, in spacewalk/setup/lib/Spacewalk/Setup.pm, and in spacewalk/admin/rhn-sat-restart-silent. That spacewalk-setup is being used by root, so no sudo is needed (and called) there. The same for Spacewalk::Setup. The spacewalk/admin/rhn-sat-restart-silent is in sudoers already by itself.

Therefore I assume /usr/sbin/rhn-satellite restart can be removed from /etc/sudoers.

Note: I did this scan through our code to figure out if there are some commands that need additional SELinux treatment.

Version-Release number of selected component (if applicable):

Satellite-5.3.0-RHEL5-re20090206.1

How reproducible:

Deterministic.

Steps to Reproduce:
1. Install Satellite 5.3.0.
2. Look into /etc/sudoers.
  
Actual results:

/usr/sbin/rhn-satellite restart is there.

Expected results:

/usr/sbin/rhn-satellite restart is not there and Satellite continues to work OK.

Additional info:

This bug was modeled based on bug 484705.
Comment 1 Jan Pazdziora 2009-02-10 07:25:28 EST
The proposed change is to remove the INSTALL_RHN section and merge whatever needs to be there to CONFIG_RHN. The proposed sudoers.rhn is below. I've tested that with this, the Satellite/Spacewalk works and runs external commands fine.

## RHN specifics ##
Cmnd_Alias CONFIG_RHN = /usr/sbin/rhn-sat-restart-silent,\
                        /usr/bin/rhn-config-satellite.pl,\
                        /usr/bin/rhn-satellite-activate,\
                        /usr/bin/rhn-bootstrap,\
                        /usr/bin/rhn-ssl-tool,\
                        /usr/bin/rhn-ssl-dbstore,\
                        /usr/bin/rhn-load-ssl-cert.pl,\
                        /etc/rc.d/np.d/step Monitoring install,\
                        /etc/rc.d/np.d/step MonitoringScout install,\
                        /etc/rc.d/np.d/step Monitoring uninstall,\
                        /etc/rc.d/np.d/step MonitoringScout uninstall,\
                        /sbin/service Monitoring restart,\
                        /sbin/service MonitoringScout restart,\
                        /sbin/service taskomatic restart

# The CONFIG_RHN commands are required for reconfiguration of a
# running RHN Satellite.  They should be enabled for proper operation
# of the RHN Satellite.
apache  ALL=(root)      NOPASSWD: CONFIG_RHN
tomcat  ALL=(root)      NOPASSWD: CONFIG_RHN

# These two directives allow tomcat and apache to invoke CONFIG_RHN
# commands via sudo even without a real tty
Defaults:tomcat !requiretty
Defaults:apache !requiretty
Comment 2 Brandon Perkins 2009-02-10 11:49:54 EST
Agreed.  The only thing we should be calling from the application is /usr/sbin/rhn-sat-restart-silent.  But we need to make sure Satellite Restart from the WebUI works.
Comment 3 Jan Pazdziora 2009-02-11 02:26:03 EST
Reassigning to myself as the bugzillas are not tracked against the SELinux feature.
Comment 4 Jan Pazdziora 2009-02-11 02:28:09 EST
The previous comment should have been "are *now*".
Comment 5 Miroslav Suchý 2009-02-12 05:17:39 EST
I will take this BZ:
I changed the calling from 
  /usr/sbin/rhn-satellite restart
to 
  /usr/sbin/rhn-sat-restart-silent
so I'm pretty sure we can safely remove it.


Commited as:
ebd8709b2cb5b304a061c58179daaf9ddc5f5135
Comment 6 Miroslav Suchý 2009-02-16 05:08:17 EST
Mass moving ON_QA
Comment 7 wes hayutin 2009-02-18 10:56:35 EST
items removed from /etc/sudoers
sat restart from webui works..

[root@grandprix ~]# cat /etc/sudoers | grep "satellite restart"
[root@grandprix ~]# cat /etc/sudoers | grep "satellite"
                         /usr/bin/rhn-config-satellite.pl,\
                         /usr/bin/rhn-satellite-activate,\
                         /usr/bin/satellite-sync,\
                        /usr/bin/rhn-config-satellite.pl,\
[root@grandprix ~]# 

verified...
Comment 8 Preethi Thomas 2009-09-02 10:39:42 EDT
release pending
[root@sun-x4200-01 ~]#  cat /etc/sudoers | grep "satellite restart"
[root@sun-x4200-01 ~]#  cat /etc/sudoers | grep "satellite"
                        /usr/bin/rhn-config-satellite.pl,\
                        /usr/bin/rhn-satellite-activate,\
Comment 9 Brandon Perkins 2009-09-10 15:11:48 EDT
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHEA-2009-1434.html

Note You need to log in before you can comment on or make changes to this bug.