Blame 0001-setfacl-the-nss-DBs-to-our-authorized-users-not-just.patch

d7b39bc
From 1a9a8eefe8f9a9b21996151a5afd956df22921ea Mon Sep 17 00:00:00 2001
d7b39bc
From: Peter Jones <pjones@redhat.com>
d7b39bc
Date: Thu, 19 Nov 2015 11:36:59 -0500
d7b39bc
Subject: [PATCH] setfacl the nss DBs to our authorized users, not just the
d7b39bc
 socket.
d7b39bc
d7b39bc
Signed-off-by: Peter Jones <pjones@redhat.com>
d7b39bc
---
d7b39bc
 src/pesign-authorize-groups | 2 ++
d7b39bc
 src/pesign-authorize-users  | 2 ++
d7b39bc
 2 files changed, 4 insertions(+)
d7b39bc
d7b39bc
diff --git a/src/pesign-authorize-groups b/src/pesign-authorize-groups
d7b39bc
index e3864ce..2236bea 100644
d7b39bc
--- a/src/pesign-authorize-groups
d7b39bc
+++ b/src/pesign-authorize-groups
d7b39bc
@@ -13,5 +13,7 @@ if [[ -r /etc/pesign/groups ]]; then
d7b39bc
     for group in $(cat /etc/pesign/groups); do
d7b39bc
         setfacl -m g:${group}:rx /var/run/pesign
d7b39bc
         setfacl -m g:${group}:rw /var/run/pesign/socket
d7b39bc
+        setfacl -m g:${username}:rx /etc/pki/pesign
d7b39bc
+        setfacl -m g:${username}:r /etc/pki/pesign/{cert8,key3,secmod}.db
d7b39bc
     done
d7b39bc
 fi
d7b39bc
diff --git a/src/pesign-authorize-users b/src/pesign-authorize-users
d7b39bc
index e500204..9c38a25 100644
d7b39bc
--- a/src/pesign-authorize-users
d7b39bc
+++ b/src/pesign-authorize-users
d7b39bc
@@ -13,5 +13,7 @@ if [[ -r /etc/pesign/users ]]; then
d7b39bc
     for username in $(cat /etc/pesign/users); do
d7b39bc
         setfacl -m u:${username}:rx /var/run/pesign
d7b39bc
         setfacl -m u:${username}:rw /var/run/pesign/socket
d7b39bc
+        setfacl -m u:${username}:rx /etc/pki/pesign
d7b39bc
+        setfacl -m u:${username}:r /etc/pki/pesign/{cert8,key3,secmod}.db
d7b39bc
     done
d7b39bc
 fi
d7b39bc
-- 
d7b39bc
2.5.0
d7b39bc