Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow sssd read symlinks in /etc/sssd #1874

Merged
merged 1 commit into from
Sep 29, 2023

Conversation

zpytela
Copy link
Contributor

@zpytela zpytela commented Sep 26, 2023

Previously, sssd was allowed to read only plain configuration files in /etc/sssd. Since this commit it is allowed to read symlinks, too, which supports a scenario where sssd_auth_ca_db.pem points to /etc/ipa/ca.crt so that cert renewals are automatically picked up, with no administrative overhead.

Resolves: SSSD/sssd#6611

Previously, sssd was allowed to read only plain configuration files in
/etc/sssd. Since this commit it is allowed to read symlinks, too, which
supports a scenario where sssd_auth_ca_db.pem points to /etc/ipa/ca.crt
so that cert renewals are automatically picked up, with no
administrative overhead.

Resolves: SSSD/sssd#6611
@zpytela zpytela merged commit c0ce82d into fedora-selinux:rawhide Sep 29, 2023
7 checks passed
@zpytela zpytela deleted the sssd-conf-link branch September 29, 2023 09:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

SELinux policy does not allow /etc/sssd/pki/sssd_auth_ca_db.pem to be a symlink
1 participant