Piotr Drąg
a96b89388d
Translated using Weblate (Polish)
...
Currently translated at 9.6% (451 of 4676 strings)
Co-authored-by: Piotr Drąg <piotrdrag@gmail.com >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/pl/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-30 11:18:37 -04:00
Christian Heimes
3ab3ed5ff2
Retry chronyc waitsync only once
...
It's unlikely that a third chrony synchronization attempt is going to
succeed after the the first two attempts have failed. Perform more
retries with smaller timeout.
This speed up installer by 11 seconds on systems without fully
configured chronyd or no chronyd (e.g. containers).
Related: https://pagure.io/freeipa/issue/8521
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Francois Cami <fcami@redhat.com >
2020-09-30 17:01:01 +02:00
Christian Heimes
38d083e344
configure_dns_resolver: call self.restore_context
...
Use the platform implementation of restore_context() instead of the base
implementation.
Fixes: https://pagure.io/freeipa/issue/8518
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-30 09:56:04 +02:00
Christian Heimes
1921d33d41
Drop unused extended sleep feature from Sleeper
...
The extended sleep feature is not used at the moment.
Related: https://pagure.io/freeipa/issue/8521
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-30 09:52:08 +02:00
Christian Heimes
b79191f710
Faster certmonger wait_for_request()
...
wait_for_request() now waits 0.5 instead of 5 seconds. This shoves off
15 to 20 seconds from ipa-server-install while marginally increased
load on the system.
request_and_wait_for_cert() now uses correct certmonger_wait_timeout
instead of http_timeout.
Related: https://pagure.io/freeipa/issue/8521
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-30 09:52:08 +02:00
Christian Heimes
aa67177f4c
Add helper for poll/sleep loops with timeout
...
The Sleeper class is a helper that makes poll/sleep loops with timeout
easier to write. It takes care of edge cases and does not oversleep
timeout deadline.
Related: https://pagure.io/freeipa/issue/8521
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-30 09:52:08 +02:00
Christian Heimes
1684b0f2c3
Add missing fedora_container platform members
...
The fedora_container platform was missing User and Group members.
Add test case to verify that all known platforms define correct module
API.
Fixes: https://pagure.io/freeipa/issue/8519
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-29 12:06:24 +02:00
Christian Heimes
9f0ec27e9f
Add more indices
...
ipaCASubjectDN is used by lightweight sub CA feature.
ipaExternalMember is used by KRB driver to assemble MS-PAC records.
ipaNTSecurityIdentifier was only index for "pres" and was missing an
index on "eq". Samba and ipasam perform queries with SID string.
memberPrincipal is used by S4U2Proxy constrained delegation and by
ipa-custodia.
Also note that dnaHostname, ipServiceProtocol, ipaCertSubject, and
ipaKeyUsage are currently not index because an index would rarely used
or have a poor selectivity.
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-29 12:05:20 +02:00
Christian Heimes
e46c3792f3
Use single update LDIF for indices
...
Index definitions were split across four files. indices.ldif contained
the initial subset of indices. Three update files partly duplicated the
indices and partly added new indices.
All indices are now defined in a single update file that is sorted
alphanumerically.
The changeset avoids two additional index tasks and reduces installation
time by 5 to 10 seconds.
Fixes: https://pagure.io/freeipa/issue/8493
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-29 12:05:20 +02:00
Christian Heimes
ced1dcb1d9
Also backup DNS config drop-ins
...
/etc/NetworkManager/conf.d and /etc/systemd/resolved.conf.d drop-in
files were not backed up.
Related: https://pagure.io/freeipa/issue/8275
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-28 14:33:15 +02:00
Christian Heimes
34e47778b4
Ensure that resolved.conf.d is accessible
...
systemd-resolved runs as user systemd-resolve. Ensure that
resolved.conf.d drop-in directory is accessible when installer runs with
restricted umask. Also ensure the file and directory has correct SELinux
context.
The parent directory /etc/systemd exists on all platforms.
Fixes: https://pagure.io/freeipa/issue/8275
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-28 14:33:15 +02:00
Alexander Bokovoy
2c393c09e0
Pre-populate IP addresses for the name server upgrades
...
Setting up resolv.conf in BIND instance expects IP addresses of the
server to be provided. This is done wiht BindInstance.setup() method
call. However, when reusing resolver setup during upgrade BIND instance
has no IP addresses configured and fails with an assert in
tasks.configure_dns_resolver().
Pass through the server's IP addresses during upgrade.
Fixes: https://pagure.io/freeipa/issue/8518
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-28 08:47:31 +02:00
Christian Heimes
6c52ef2b64
Fix compiler warning in ipa-kdb
...
Make assertion_value a const char*
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:43:42 +03:00
Christian Heimes
7de2c9bc82
Fix compiler warnings in libotp
...
Remove unused variable declarations
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:43:42 +03:00
Christian Heimes
6fde06ac30
Fix compiler warning in ipa-pwd-extop
...
cast const error message to non-const char*. I tried to make errMesg a
const char* but it gets passed down to slapi_send_ldap_result() which
accepts a char*.
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:43:42 +03:00
Christian Heimes
4e30a48d3c
trust-add: Catch correct exception when chown SSSD
...
Commit 72fb4e6 introduced a regression. SSSD_USER.chown() raises
ValueError instead of KeyError when SSSD user does not exist.
Fixes: https://pagure.io/freeipa/issue/8516
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Florence Blanc-Renaud <flo@redhat.com >
2020-09-26 10:41:32 +03:00
Emilio Herrera
4cc9c942d1
Translated using Weblate (Spanish)
...
Currently translated at 60.8% (2845 of 4676 strings)
Translated using Weblate (Spanish)
Currently translated at 60.8% (2844 of 4676 strings)
Co-authored-by: Emilio Herrera <ehespinosa57@gmail.com >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/es/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Oğuz Ersen
0464a5ffff
Translated using Weblate (Turkish)
...
Currently translated at 7.6% (358 of 4676 strings)
Co-authored-by: Oğuz Ersen <oguzersen@protonmail.com >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/tr/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Yuri Chornoivan
abc416407e
Translated using Weblate (Ukrainian)
...
Currently translated at 100.0% (4676 of 4676 strings)
Translated using Weblate (Ukrainian)
Currently translated at 100.0% (4676 of 4676 strings)
Co-authored-by: Yuri Chornoivan <yurchor@ukr.net >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/uk/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Weblate
afa0f5d187
Update translation files
...
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Co-authored-by: Weblate <noreply@weblate.org >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Daniel Lara Souza
11828cf87c
Translated using Weblate (Portuguese (Brazil))
...
Currently translated at 3.5% (167 of 4654 strings)
Co-authored-by: Daniel Lara Souza <daniellarasouza@yahoo.com.br >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/pt_BR/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Weblate
90c1a00f04
Update translation files
...
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Co-authored-by: Weblate <noreply@weblate.org >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Yuri Chornoivan
a330adae8a
Translated using Weblate (Ukrainian)
...
Currently translated at 100.0% (4654 of 4654 strings)
Translated using Weblate (Ukrainian)
Currently translated at 98.8% (4600 of 4654 strings)
Co-authored-by: Yuri Chornoivan <yurchor@ukr.net >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/uk/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Weblate
89d8518266
Update translation files
...
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Update translation files
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Co-authored-by: Weblate <noreply@weblate.org >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Rafael Fontenelle
1eaa5974e4
Translated using Weblate (Portuguese (Brazil))
...
Currently translated at 3.2% (153 of 4654 strings)
Co-authored-by: Rafael Fontenelle <rafaelff@gnome.org >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/pt_BR/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Weblate
a2f7e917a1
Update translation files
...
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Update translation files
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Co-authored-by: Weblate <noreply@weblate.org >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Oğuz Ersen
54dff05cd2
Translated using Weblate (Turkish)
...
Currently translated at 7.6% (357 of 4654 strings)
Translation: freeipa/master
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/tr/
Translated using Weblate (Turkish)
Currently translated at 7.3% (342 of 4654 strings)
Translation: freeipa/master
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/tr/
Translated using Weblate (Turkish)
Currently translated at 4.6% (216 of 4654 strings)
Translation: freeipa/master
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/tr/
Translated using Weblate (Turkish)
Currently translated at 0.7% (34 of 4654 strings)
Translation: freeipa/master
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/tr/
Added translation using Weblate (Turkish)
Co-authored-by: Oğuz Ersen <oguzersen@protonmail.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Christian Heimes
69ebe41525
Fix nsslapd-db-lock tuning of BDB backend
...
nsslapd-db-lock was moved from cn=config,cn=ldbm database,cn=plugins,cn=config
entry to cn=bdb subentry. Manual patching of dse.ldif was no longer
working. Installations with 389-DS 1.4.3 and newer are affected.
Low lock count can affect performance during high load, e.g. mass-import
of users or lots of concurrent connections.
Bump minimal DS version to 1.4.3. Fedora 32 and RHEL 8.3 have 1.4.3.
Fixes: https://pagure.io/freeipa/issue/8515
See: https://pagure.io/freeipa/issue/5914
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Francois Cami <fcami@redhat.com >
2020-09-24 17:03:00 +02:00
Serhii Tsymbaliuk
29b41aef0a
WebUI: Fix jQuery DOM manipulation issues
...
The commit includes the following jQuery patches:
- Manipulation: Make jQuery.htmlPrefilter an identity function
(https://github.com/jquery/jquery/pull/4642 )
- Manipulation: Skip the select wrapper for <option> outside of IE 9
(https://github.com/jquery/jquery/pull/4647 )
In addition there is included a script that helps to patch and build
the new version of jQuery:
$ install/ui/util/make-jquery.js 3.4.1
Ticket: https://pagure.io/freeipa/issue/8507
Signed-off-by: Serhii Tsymbaliuk <stsymbal@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-24 16:21:04 +02:00
Rob Crittenden
b47ddb0186
Reduce the memory requirement from 1.6 to 1.2 GB
...
We know from practical experience in PR-CI and Azure that 1.2
is the absolute minimum necessary for a base installation.
https://pagure.io/freeipa/issue/8404
Signed-off-by: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-24 08:20:48 +02:00
Christian Heimes
79b9982b86
Create systemd-resolved configuration on update
...
Create systemd-resolved drop-in and restart the service when the drop-in
config file is missing and /etc/resolv.conf points to stub resolver
config file.
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 16:44:26 +02:00
Christian Heimes
d12f1b4b39
Configure systemd-resolved to use IPA's BIND
...
IPA installer now instructs systemd-resolved to use IPA's BIND DNS
server as primary DNS server.
Fixes: https://pagure.io/freeipa/issue/8275
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 16:44:26 +02:00
Christian Heimes
528c519cb5
Use new API for auto-forwarders
...
Auto-forwarders and manual configuration now use the new API to get a
list of DNS servers. Manual installer refuses loopback, too.
See: https://pagure.io/freeipa/issue/8275
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 16:44:26 +02:00
Christian Heimes
e64f27fdf8
Configure NetworkManager to use systemd-resolved
...
zzz-ipa.conf now enables NetworkManager's systemd-resolved plugin when
systemd-resolved is detected.
See: https://pagure.io/freeipa/issue/8275
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 16:44:26 +02:00
Christian Heimes
96edff0b8c
Add helpers for resolve1 and nameservers
...
detect_resolve1_resolv_conf() detects if systemd-resolved is enabled and
manages /etc/resolv.conf.
get_resolve1_nameservers() gets upstream DNS servers from
systemd-resolved's D-Bus interface.
get_dnspython_nameservers() gets upstream DNS servers from
/etc/resolv.conf via dns.python.
get_nameservers() gets a list of unique, non-loopback DNS server IP
addresses.
Also fixes setup.py to include D-Bus for ipalib instead of ipapython.
See: https://pagure.io/freeipa/issue/8275
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 16:44:26 +02:00
Zdenek Pytela
7651d335b3
Add ipa_pki_retrieve_key_exec() interface
...
The ipa_pki_retrieve_key_exec() interface is needed to allow other
domains execute ipa-pki-retrieve-key.
Related: https://pagure.io/freeipa/issue/8488
Signed-off-by: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-23 15:23:28 +02:00
Christian Heimes
644bd0e46b
Make git a build requirement
...
FreeIPA uses git in its build process. In the past git was automatically
pulled in. On Fedora 33 builds are failing because git is missing.
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-23 14:49:56 +02:00
Christian Heimes
80fca8d701
Delay import of psutil to avoid AVC
...
Commit cfad7af35d added a check to ensure a
system has sufficient amount of memory. The feature uses psutil to get
available memory. On import psutil opens files in /proc which can result in
an SELinux violations and Python exception.
PermissionError: [Errno 13] Permission denied: '/proc/stat'
Fixes: https://pagure.io/freeipa/issue/8512
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 14:49:15 +02:00
Rob Crittenden
9f9dcfe88a
Test that ccaches are cleaned up during installation
...
Create a random file and directory in the ccaches directory
prior to installation then confirm that they were removed.
https://pagure.io/freeipa/issue/8248
Signed-off-by: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-23 14:48:29 +02:00
Rob Crittenden
cc5d9a8c9d
Clean up entire /run/ipa/ccaches directory not just files
...
If there are any sub-directories in the ccaches directory
then cleaning it up will fail.
Instead remove the whole directory and allow systemd-tmpfiles
to re-create it.
https://pagure.io/freeipa/issue/8248
Signed-off-by: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-23 14:48:29 +02:00
François Cami
36c6a2e749
SELinux: do not double-define node_t and pki_tomcat_cert_t
...
node_t and pki_tomcat_cert_t are defined in other modules.
Do not double-define them.
Fixes: https://pagure.io/freeipa/issue/8513
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-23 14:47:06 +02:00
Rob Crittenden
84bbf68781
Require a matching server package for the selinux subpackage
...
Ensure that the selinux subpackage is upgraded along with the
rest of IPA if it is built.
https://pagure.io/freeipa/issue/8511
Signed-off-by: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Francois Cami <fcami@redhat.com >
2020-09-22 19:30:03 -04:00
François Cami
2f2bce4310
SELinux Policy: Allow tomcat_t to read kerberos keytabs
...
This is required to fix:
avc: denied { search } for pid=1930 comm="ipa-pki-retriev" name="krb5" dev="dm-0" ino=8620822 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:krb5_keytab_t:s0 tclass=dir permissive=0
Macros suggested by: Ondrej Mosnacek
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
f774642b63
SELinux Policy: make interfaces for kernel modules non-optional
...
Interfaces for kernel modules do not need to be in an optional module.
Also make sure ipa_custodia_t can log.
Suggested by Lukas Vrabec.
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
4b3c4b84d4
SELinux Policy: flag ipa_pki_retrieve_key_exec_t as domain_type
...
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
09816f4dbc
SELinux Policy: ipa_custodia_pki_tomcat_exec_t => ipa_custodia_pki_tomcat_t
...
ipa_custodia_pki_tomcat_exec_t was granted java_exec by mistake ; replace by
ipa_custodia_pki_tomcat_t.
As suggested by Ondrej Mosnáček.
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
820beca4ac
SELinux Policy: ipa_pki_retrieve_key_exec_t => ipa_pki_retrieve_key_t
...
Grant pki_manage_tomcat_etc_rw to ipa_pki_retrieve_key_t instead of
ipa_pki_retrieve_key_exec_t.
As suggested by Ondrej Mosnáček.
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
ea9db4a903
SELinux Policy: let custodia_t map custodia_tmp_t
...
This is used by the JVM perf counters.
Related: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
7823da0630
SELinux: Add dedicated policy for ipa-pki-retrieve-key
...
Add proper labeling, transition and policy for ipa-pki-retrieve-key.
Make sure tomcat_t can execute ipa-pki-retrieve-key.
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
dfeea1644a
ipatests: enhance TestSubCAkeyReplication
...
enhance the test suite so that it covers:
- deleting subCAs (disabling them first)
- checking what happens when creating a dozen+ subCAs at a time
- adding a subCA that already exists and expect failure
Related: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00