Project

General

Profile

Actions

Bug #35093

open

Missing selinux rule for ssh + puma + kerberos

Added by Ben Magistro over 2 years ago. Updated over 2 years ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Difficulty:
Triaged:
No
Fixed in Releases:
Found in Releases:

Description

OS: CentOS 7.9
TFM: 2.1.4 (upgrades in progress)

We utilize kerberos tickets for ssh instead of keys. All hosts are joined to the domain for authentication leveraging sssd. With selinux enabled foreman is unable to connect to our libvirt instances. Shifting selinux to permissive allows it to connect. I haven't had a chance to dig into what a possible rule to address this would look like for this yet.

Actions

Also available in: Atom PDF