Bug 841933 - pwconv create /etc/shadow with bad SELinux context
pwconv create /etc/shadow with bad SELinux context
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: shadow-utils (Show other bugs)
All Linux
high Severity low
: rc
: ---
Assigned To: Peter Vrabec
BaseOS QE Security Team
Depends On:
  Show dependency treegraph
Reported: 2012-07-20 11:14 EDT by Miroslav Vadkerti
Modified: 2012-07-23 11:20 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2012-07-23 11:20:48 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Miroslav Vadkerti 2012-07-20 11:14:56 EDT
Description of problem:
pwconv creates /etc/shadow with incorrect context -> this then breaks the system  quite bad.

# ll -Z /etc/shadow*
-r--------. root root system_u:object_r:shadow_t:s0    /etc/shadow
----------. root root system_u:object_r:shadow_t:s0    /etc/shadow-
# pwunconv
# pwconv 
# ll -Z /etc/shadow*
-r--------. root root unconfined_u:object_r:etc_t:s0   /etc/shadow
----------. root root system_u:object_r:shadow_t:s0    /etc/shadow-

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. pwunconv
2. pwconv
3. ll -Z /etc/shadow*
Actual results:
/etc/shadow has incorrect SELinux context

Expected results:
/etc/shadow has correct SELinux context
Comment 1 Peter Vrabec 2012-07-23 11:20:48 EDT
fixed in shadow-utils >= 4.1.5-2

* Wed Mar 22 2012 Peter Vrabec <pvrabec@redhat.com> - 2:4.1.5-2
- fix selinux context handling
- reset selinux context on files copied from skel

Note You need to log in before you can comment on or make changes to this bug.