You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Some command line tools we have could run unprivileged. The tools should still make sure they were executed by root and then drop the privileges to the sssd user.
The tools that could run unprivileged are sss_seed and sss_cache. Depending on whether upstream changes the permissions of sssd.conf to sssd.sssd from root.root also sss_debuglevel and sss_obfuscate.
I don't think this ticket is a high priority, because in general the tools don't accept any input and don't stay around for too long, so the chance of them being compromised is small.
Thank you for taking time to submit this request for SSSD. Unfortunately this issue was not given priority and the team lacks the capacity to work on it at this time.
Given that we are unable to fulfill this request I am closing the issue as wontfix.
If the issue still persist on recent SSSD you can request re-consideration of this decision by reopening this issue. Please provide additional technical details about its importance to you.
Cloned from Pagure issue: https://pagure.io/SSSD/sssd/issue/2500
Some command line tools we have could run unprivileged. The tools should still make sure they were executed by root and then drop the privileges to the sssd user.
The tools that could run unprivileged are sss_seed and sss_cache. Depending on whether upstream changes the permissions of sssd.conf to sssd.sssd from root.root also sss_debuglevel and sss_obfuscate.
I don't think this ticket is a high priority, because in general the tools don't accept any input and don't stay around for too long, so the chance of them being compromised is small.
Comments
Comment from jhrozek at 2014-11-21 20:25:30
Fields changed
type: defect => enhancement
Comment from jhrozek at 2014-12-04 17:31:45
Fields changed
milestone: NEEDS_TRIAGE => SSSD Deferred
Comment from jhrozek at 2015-03-17 11:23:27
Fields changed
rhbz: => todo
Comment from jhrozek at 2017-02-24 14:23:20
Metadata Update from @jhrozek:
Comment from pbrezina at 2020-03-24 14:17:36
Thank you for taking time to submit this request for SSSD. Unfortunately this issue was not given priority and the team lacks the capacity to work on it at this time.
Given that we are unable to fulfill this request I am closing the issue as wontfix.
If the issue still persist on recent SSSD you can request re-consideration of this decision by reopening this issue. Please provide additional technical details about its importance to you.
Thank you for understanding.
Comment from pbrezina at 2020-03-24 14:17:38
Metadata Update from @pbrezina:
The text was updated successfully, but these errors were encountered: