mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2024-12-23 07:33:27 -06:00
beffa7bcda
Implement the import and export handlers for Custodia keys as external scripts. It's a prerequisite to drop DAC override permission and proper SELinux rules for ipa-custodia. Except for DMLDAP, handlers no longer run as root but as handler specific users with reduced privileges. The Dogtag-related handlers run as pkiuser, which also help with HSM support. The export and import handles are designed to be executed by sudo, too. In the future, ipa-custodia could be executed as an unprivileged process that runs the minimal helper scripts with higher privileges. Fixes: https://pagure.io/freeipa/issue/6888 Signed-off-by: Christian Heimes <cheimes@redhat.com> Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
22 lines
488 B
Makefile
22 lines
488 B
Makefile
NULL =
|
|
|
|
appdir = $(libexecdir)/ipa/custodia/
|
|
nodist_app_SCRIPTS = \
|
|
ipa-custodia-dmldap \
|
|
ipa-custodia-pki-tomcat \
|
|
ipa-custodia-pki-tomcat-wrapped \
|
|
ipa-custodia-ra-agent \
|
|
$(NULL)
|
|
|
|
dist_noinst_DATA = \
|
|
ipa-custodia-dmldap.in \
|
|
ipa-custodia-pki-tomcat.in \
|
|
ipa-custodia-pki-tomcat-wrapped.in \
|
|
ipa-custodia-ra-agent.in \
|
|
$(NULL)
|
|
|
|
PYTHON_SHEBANG = $(nodist_app_SCRIPTS)
|
|
|
|
CLEANFILES = $(PYTHON_SHEBANG)
|
|
|
|
include $(top_srcdir)/Makefile.pythonscripts.am |