Bug#1001377: sssd-dbus: sssd_ifp messes up existing /var/log/sssd/p11_child.log permissions

2021-12-09 Thread Martin Pitt
Control: retitle -1 pam_sss messes up existing /var/log/sssd/p11_child.log permissions Control: reassign -1 libpam-sss 2.6.1-1 Control: severity -1 important Turns out this is both much simpler to reproduce and also much more severe -- one doesn't actually need all the certificate setup and

Bug#1001377: sssd-dbus: sssd_ifp messes up existing /var/log/sssd/p11_child.log permissions

2021-12-09 Thread Martin Pitt
Package: sssd-dbus Version: 2.6.1-1 I am testing the new FindByValidCertificate() infopipe API from 2.6.1, to provide safe certificate authentication for cockpit. During that I ran into a curious bug, where triggering p11-kit validation in sssd messes up the permissions of