[Bug 1859422] Re: security: default ownership and permissions
Launchpad Bug Tracker
1859422 at bugs.launchpad.net
Fri Apr 17 17:47:05 UTC 2020
This bug was fixed in the package nova - 2:21.0.0~b3~git2020041013
.57ff308d6d-0ubuntu2
---------------
nova (2:21.0.0~b3~git2020041013.57ff308d6d-0ubuntu2) focal; urgency=medium
* d/tests/nova-daemons: Skip validation that nova-scheduler is
running; this serivce requires configuration of both keystone and
the placement service which is beyond the scope of a single unit
autopkgtest.
* d/tests/control: Install nova-spiceproxy instead of nova-novncproxy
during testing as SPICE is the console option supported in Ubuntu
main.
-- James Page <james.page at ubuntu.com> Fri, 17 Apr 2020 09:48:19 +0100
** Changed in: nova (Ubuntu)
Status: Triaged => Fix Released
--
You received this bug notification because you are a member of Ubuntu
OpenStack, which is subscribed to cinder in Ubuntu.
https://bugs.launchpad.net/bugs/1859422
Title:
security: default ownership and permissions
Status in aodh package in Ubuntu:
Fix Released
Status in barbican package in Ubuntu:
Fix Released
Status in cinder package in Ubuntu:
Fix Released
Status in designate package in Ubuntu:
Fix Released
Status in glance package in Ubuntu:
Fix Released
Status in gnocchi package in Ubuntu:
Fix Released
Status in heat package in Ubuntu:
Fix Released
Status in ironic package in Ubuntu:
Fix Released
Status in ironic-inspector package in Ubuntu:
Fix Released
Status in keystone package in Ubuntu:
Fix Released
Status in magnum package in Ubuntu:
Fix Released
Status in manila package in Ubuntu:
Fix Released
Status in masakari package in Ubuntu:
Fix Released
Status in masakari-monitors package in Ubuntu:
Fix Released
Status in mistral package in Ubuntu:
Fix Released
Status in murano package in Ubuntu:
Fix Released
Status in murano-agent package in Ubuntu:
Fix Released
Status in neutron package in Ubuntu:
Fix Released
Status in nova package in Ubuntu:
Fix Released
Status in octavia package in Ubuntu:
Fix Released
Status in openstack-trove package in Ubuntu:
Fix Released
Status in placement package in Ubuntu:
Fix Released
Status in python-glance-store package in Ubuntu:
Fix Released
Status in sahara package in Ubuntu:
Fix Released
Status in senlin package in Ubuntu:
Triaged
Status in swift package in Ubuntu:
Fix Released
Status in watcher package in Ubuntu:
Fix Released
Status in zaqar package in Ubuntu:
Fix Released
Status in zvmcloudconnector package in Ubuntu:
Fix Released
Bug description:
Package should security directories and files as below:
chown <pkg>:adm /var/log/<pkg>
chmod 0750 /var/log/<pkg>
find /etc/<pkg> -exec chown root:<pkg> "{}" +
find /etc/<pkg> -type f -exec chmod 0640 "{}" + -o -type d -exec chmod 0750 "{}" +
# Optional rootwrap.d configuration files.
find /etc/<pkg>/rootwrap.d -exec chown root:root "{}" +
find /etc/<pkg>/rootwrap.d -type f -exec chmod 0644 "{}" + -o -type d -exec chmod 0755 "{}" +
find /var/lib/<pkg> -exec chown <pkg>:<pkg> "{}" +
find /var/lib/<pkg> -type f -exec chmod 0640 "{}" + -o -type d -exec chmod 0750 "{}" +
For keystone, /etc/ files/directories should be owned by
keystone:keystone: https://docs.openstack.org/security-
guide/identity/checklist.html
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/aodh/+bug/1859422/+subscriptions
More information about the Ubuntu-openstack-bugs
mailing list