[Freeipa-users] Re: /etc/ipa/nssdb label

2022-11-11 Thread Rob Crittenden via FreeIPA-users
Alexander Bokovoy via FreeIPA-users wrote: > On pe, 11 marras 2022, Sam Morris via FreeIPA-users wrote: >> Hi folks >> >> I've got a container image into which I bind mount /etc/ipa so that >> freeipa-client works. >> >> I noticed[0] that /etc/ipa/nssdb is not accessible inside the >> container, be

[Freeipa-users] Re: /etc/ipa/nssdb label

2022-11-11 Thread Alexander Bokovoy via FreeIPA-users
On pe, 11 marras 2022, Sam Morris via FreeIPA-users wrote: Hi folks I've got a container image into which I bind mount /etc/ipa so that freeipa-client works. I noticed[0] that /etc/ipa/nssdb is not accessible inside the container, because it is labelled with cert_t. SELinux policy prevents

[Freeipa-users] /etc/ipa/nssdb label

2022-11-11 Thread Sam Morris via FreeIPA-users
Hi folks I've got a container image into which I bind mount /etc/ipa so that freeipa-client works. I noticed[0] that /etc/ipa/nssdb is not accessible inside the container, because it is labelled with cert_t. SELinux policy prevents container_t from reading files labelled with cert_t. As I