Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

selinux: disable ipa_custodia when installing custom policy #4418

Closed
wants to merge 1 commit into from

Conversation

vmojzis
Copy link
Contributor

@vmojzis vmojzis commented Mar 23, 2020

Since ipa_custodia got integrated into ipa policy package, the upstream policy
module needs to be disabled before ipa module installation (in order to be able
to make changes to the ipa_custodia policy definitions).
Upstream ipa module gets overridden automatically because of higher priority of
the custom module, but there is no mechanism to automatically disable
ipa_custodia.

Related: https://pagure.io/freeipa/issue/6891

Since ipa_custodia got integrated into ipa policy package, the upstream policy
module needs to be disabled before ipa module installation (in order to be able
to make changes to the ipa_custodia policy definitions).
Upstream ipa module gets overridden automatically because of higher priority of
the custom module, but there is no mechanism to automatically disable
ipa_custodia.

Related: https://pagure.io/freeipa/issue/6891
@abbra abbra added ipa-4-8 Mark for backport to ipa 4.8 re-run Trigger a new run of PR-CI labels Mar 23, 2020
@abbra
Copy link
Contributor

abbra commented Mar 23, 2020

LGTM, I started PR CI tests.

@freeipa-pr-ci freeipa-pr-ci removed the re-run Trigger a new run of PR-CI label Mar 23, 2020
@abbra abbra added ack Pull Request approved, can be merged pushed Pull Request has already been pushed labels Mar 24, 2020
@abbra
Copy link
Contributor

abbra commented Mar 24, 2020

master:

  • 3aad16a selinux: disable ipa_custodia when installing custom policy

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ack Pull Request approved, can be merged ipa-4-8 Mark for backport to ipa 4.8 pushed Pull Request has already been pushed
Projects
None yet
3 participants