[Freeipa-devel] [PATCH 012] Fix selinux denial during kdcproxy user creation

Christian Heimes cheimes at redhat.com
Thu Jul 16 11:49:00 UTC 2015


On 2015-07-16 13:46, Tomas Babej wrote:
> 
> 
> On 07/16/2015 01:35 PM, Christian Heimes wrote:
>> On 2015-07-16 12:51, Christian Heimes wrote:
>>> Hi,
>>>
>>> the patch fixes the SELinux denial for kdcproxy's home directory. I have
>>> successfully tested a migration from FreeIPA 4.1. The user, group and
>>> home directory are successfully created with the correct permissions.
>>>
>>> https://fedorahosted.org/freeipa/ticket/5135
>>
>> I accidentally pushed the spec file fix for PKI. Here is the correct
>> patch for FreeIPA.
>>
>>
>>
> 
> ACK! Thanks for fixing this issue, actually it was haunting me for some
> time as I was unable to pinpoint the issue.
> 
> Pushed to:
> master: 0700d340c7c88c295a62dd5d1a7d6866650d9de3
> ipa-4-2: 9c3368a3eb091acab10b65ff3fc33d41d0d4c556

You are welcome! Alexander deserves most of the credit for the patch. He
analyzed the issue and explained it to me. The patch was a matter of
minutes to write.

Christian

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 455 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20150716/c51fef1f/attachment.sig>


More information about the Freeipa-devel mailing list