Re: [Freeipa-users] ipa-getcert and SELinux

2016-03-14 Thread Thomas Raehalme
Hi! On Mon, Mar 7, 2016 at 11:20 PM, Rob Crittenden wrote: > It may be preferable to label the /var/lib/puppet/ssl/* directories as > certmonger_var_lib_t but I don't know what would do to puppet. You could > trade one problem for another. A BZ against selinux might be warranted > to see what th

Re: [Freeipa-users] ipa-getcert and SELinux

2016-03-09 Thread Martin Kosek
On 03/07/2016 10:03 PM, Thomas Raehalme wrote: > Hi! > > I have setup certificates for Puppet as described here: > http://www.freeipa.org/page/Using_IPA's_CA_for_Puppet > > Unfortunately SELinux is giving me hard time when invoking "ipa-getcert > request" to generate the private/public key for th

Re: [Freeipa-users] ipa-getcert and SELinux

2016-03-07 Thread Rob Crittenden
Thomas Raehalme wrote: > Hi! > > I have setup certificates for Puppet as described here: > http://www.freeipa.org/page/Using_IPA's_CA_for_Puppet > > Unfortunately SELinux is giving me hard time when invoking "ipa-getcert > request" to generate the private/public key for the Puppet agent > (permis

[Freeipa-users] ipa-getcert and SELinux

2016-03-07 Thread Thomas Raehalme
Hi! I have setup certificates for Puppet as described here: http://www.freeipa.org/page/Using_IPA's_CA_for_Puppet Unfortunately SELinux is giving me hard time when invoking "ipa-getcert request" to generate the private/public key for the Puppet agent (permission denied when trying to write the ke