#185 enhance SELinux support
Closed: Invalid None Opened 14 years ago by sbose.

  • sssd_pam should call getpeercon(3) and make the context available to other components
  • Kerberos provider should create credential cache file with right SELinux labels

Looks like a nice-to-have, not a need-to-have for 1.0.

milestone: SSSD 1.0 => SSSD Deferred

Fields changed

milestone: SSSD Deferred => SSSD 1.1

After a couple of discussions it was decided that there is no need of a change here. The credential cache file is always created by the krb5_child helper process running with the user id of the user requesting the ticket. As a consequence the credential cache file is labeled appropriate. For example if the file is created in /tmp is has the type user_tmp_t.

resolution: => wontfix
status: new => closed

Metadata Update from @sbose:
- Issue assigned to sbose
- Issue set to the milestone: SSSD 1.1

7 years ago

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/1227

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Login to comment on this ticket.

Metadata