During upgrate the http.keytab is moved to a new location but with incorrect SELinux context. Operation copy and remove should be used instead of move to restore context properly.
copy
remove
move
Note from SELinux team:
Label of http.keytab is preserved, this should be change and label for http.keytab should be ipa_var_lib_t instead of httpd_config_t.
Metadata Update from @pvoborni: - Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1447703
Issue linked to bug 1447703
Metadata Update from @mbasti: - Issue assigned to mbasti
master:
7f4c2fb Use proper SELinux context with http.keytab ipa-4-5:
bda733d Use proper SELinux context with http.keytab
Metadata Update from @mbabinsk: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
Metadata Update from @mbasti: - Issue set to the milestone: FreeIPA 4.5.1
Log in to comment on this ticket.