[JIRA] Commented: (SSPCPP-353) Package the SP to run as non-root user

Scott Cantor (JIRA) noreply at shibboleth.net
Tue Aug 16 15:38:25 BST 2011


    [ https://issues.shibboleth.net/jira/browse/SSPCPP-353?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13486#comment-13486 ] 

Scott Cantor commented on SSPCPP-353:
-------------------------------------

Both, really, at least in the log case. The point is you're (potentially) creating an upgrade from root owning the files and folders to the user. I don't know if putting %attr on the directory will actually change an existing directory. I think I found that it did not, but you might try that.

Using the init script is a possibility, I guess, though it's ugly. SUSE doesn't have a way to block that, it just prohibits doing it in %post

> Package the SP to run as non-root user
> --------------------------------------
>
>                 Key: SSPCPP-353
>                 URL: https://issues.shibboleth.net/jira/browse/SSPCPP-353
>             Project: Shibboleth SP - C++
>          Issue Type: Improvement
>          Components: Installation
>    Affects Versions: 2.4, 2.4.1, 2.4.2, 2.4.3
>         Environment: CentOS 5.5 / Shibboleth 2.3.1 from openSUSE repos
>            Reporter: Takeshi NISHIMURA
>            Assignee: Scott Cantor
>            Priority: Minor
>         Attachments: shibd-runuser.diff
>
>   Original Estimate: 1 week
>  Remaining Estimate: 1 week
>
> Updating Shibboleth SP by "yum update" changes owner:group and permissions of /var/{run,log}/shibboleth to the default (root:root and rwxrwxr-x) even if they already exist. Please preserve these permissions on updates if they already exist.
> I am running shibd with user "shibboleth".
> I am using those directories with following permissions:
> rwxrwxr-x root:shibboleth /var/log/shibboleth
> rwxrwxr-x root:shibboleth /var/run/shibboleth
> , and had troubles on every recent updates.

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira


More information about the commits mailing list