mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2026-10-06 13:46:46 -05:00
SSSD ships passkey_child binary in /usr/libexec/sssd and it needs the same security context as /usr/libexec/sssd/oidc_child (ipa_otpd_exec_t type). Add the context in the SELinux policy provided by IPA. Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=2169438 Signed-off-by: Florence Blanc-Renaud <flo@redhat.com> Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
IPA SELinux policy
The ipa SELinux policy is used by IPA client and server. The
policy was forked off from Fedora upstream policy
at commit b1751347f4af99de8c88630e2f8d0a352d7f5937.
Some file locations are owned by other policies:
/var/lib/ipa/pki-ca/publish(/.*)?is owned by Dogtag PKI policy/usr/lib/ipa/certmonger(/.*)?is owned by certmonger policy/var/lib/ipa-client(/.*)?is owned by realmd policy