Project

General

Profile

Actions

Feature #4464

closed

Implement SELinux policy for smart-proxy

Added by Lukas Zapletal over 10 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Urgent
Category:
Packaging
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

Now the question is how deep we want to go. Smart proxy can be configured to spawn virsh via sudo and other stuff. I guess we should limit what is covered by the policy.

Actions #1

Updated by Dominic Cleal over 10 years ago

Agreed... the trouble is also that the proxy codebase is messy and it has a lot of ugly implementations. I think the policy should probably be very tunable depending on what type of work the proxy is configured for.

Actions #2

Updated by Lukas Zapletal over 10 years ago

  • Priority changed from Normal to High

OSP guys rely on this feature, boosting priority: https://bugzilla.redhat.com/show_bug.cgi?id=1105154

Actions #3

Updated by Lukas Zapletal about 10 years ago

  • Target version set to 1.7.5
Actions #4

Updated by Lukas Zapletal about 10 years ago

  • Status changed from New to Assigned
  • Assignee set to Lukas Zapletal
  • Priority changed from High to Urgent

Yup, it's official. I started works on the foreman-proxy policy.

Actions #5

Updated by The Foreman Bot about 10 years ago

  • Status changed from Assigned to Ready For Testing
  • Pull request https://github.com/theforeman/smart-proxy/pull/201 added
  • Pull request deleted ()
Actions #6

Updated by Dominic Cleal about 10 years ago

  • Status changed from Ready For Testing to Assigned
Actions #7

Updated by Anonymous about 10 years ago

  • Target version changed from 1.7.5 to 1.7.4
Actions #8

Updated by The Foreman Bot about 10 years ago

  • Status changed from Assigned to Ready For Testing
Actions #9

Updated by Anonymous about 10 years ago

  • Target version changed from 1.7.4 to 1.7.3
Actions #10

Updated by Dominic Cleal about 10 years ago

  • Target version changed from 1.7.3 to 1.7.2
Actions #11

Updated by Dominic Cleal almost 10 years ago

  • Translation missing: en.field_release set to 28
Actions #12

Updated by Anonymous almost 10 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
Actions

Also available in: Atom PDF