Architecture #6517
closed
User story #6589: Improve Rudder security in 3.1: Inventory signature and security, SELinux compliance
User story #2882: Rudder should be SELinux compliant
Authorize on SELinux directories used for webdav on the server
Added by François ARMAND over 9 years ago.
Updated over 9 years ago.
Category:
System integration
Description
We need the rule to authorize read/write/delete from Apache webdav (and our send-clean scrip ?) on the directories used to store inventories (see question #6467)
I guess adding:
- setsebool -P httpd_can_network_connect on
- chcon -Rv --type=httpd_sys_content_t /var/rudder/inventories
Would certainly be enough :)
- Status changed from New to Pending technical review
- Assignee changed from Matthieu CERDA to Benoît PECCATTE
- % Done changed from 0 to 100
- Pull Request set to https://github.com/Normation/rudder-packages/pull/638
- Pull Request changed from https://github.com/Normation/rudder-packages/pull/638 to https://github.com/Normation/rudder-packages/pull/639
- Status changed from Pending technical review to Pending release
- Status changed from Pending release to Released
This bug has been fixed in Rudder 3.1.0~beta1 which were released today.
Also available in: Atom
PDF