Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.

Bug 1073492

Summary: selinux avc for httpd accessing KEYRING ccache type
Product: Red Hat Enterprise Linux 7 Reporter: Simo Sorce <ssorce>
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED CURRENTRELEASE QA Contact: Milos Malik <mmalik>
Severity: medium Docs Contact:
Priority: medium    
Version: 7.0CC: abokovoy, dominick.grift, dpal, dwalsh, jpazdziora, ksrot, lvrabec, mgrepl, mkosek, mmalik, pviktori, rcritten
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: selinux-policy-3.12.1-133.el7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 1063827 Environment:
Last Closed: 2014-06-13 11:17:46 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1063827    
Bug Blocks: 991169    

Comment 3 Martin Kosek 2014-03-06 14:37:00 UTC
With regards to IPA server changes, we are ok with having the fix in 7.1.

Comment 4 Simo Sorce 2014-03-06 14:55:49 UTC
Just wanted to make sure this is in for RHEL 7.0, this issue is a general issue that will hit any daemon that wants to interact with the kernel keyring.

Comment 5 Miroslav Grepl 2014-03-06 16:11:46 UTC
We have policy fixes in Fedora which are going to RHEL7.

Comment 9 Ludek Smid 2014-06-13 11:17:46 UTC
This request was resolved in Red Hat Enterprise Linux 7.0.

Contact your manager or support representative in case you have further questions about the request.