summaryrefslogtreecommitdiffstats
path: root/base/server/scripts
diff options
context:
space:
mode:
authorEndi S. Dewata <edewata@redhat.com>2016-07-22 17:31:20 +0200
committerEndi S. Dewata <edewata@redhat.com>2016-07-26 21:18:20 +0200
commit9e77b42d88da07e91a42966bc2d1ea9237e62f47 (patch)
treec3b92f8ebb1eac3b74972f2c12758c97a48959bf /base/server/scripts
parent3f4c9e4e7946f3f330b71cfe36a00ae933de2575 (diff)
downloadpki-9e77b42d88da07e91a42966bc2d1ea9237e62f47.tar.gz
pki-9e77b42d88da07e91a42966bc2d1ea9237e62f47.tar.xz
pki-9e77b42d88da07e91a42966bc2d1ea9237e62f47.zip
Removed hard-coded paths in pki.policy.
The operations script has been modified to generate pki.policy dynamically from links in the <instance>/common/lib directory. This allows the pki.policy to match the actual paths in different platforms. https://fedorahosted.org/pki/ticket/2403
Diffstat (limited to 'base/server/scripts')
-rw-r--r--base/server/scripts/operations16
1 files changed, 15 insertions, 1 deletions
diff --git a/base/server/scripts/operations b/base/server/scripts/operations
index 14443c4a5..599167008 100644
--- a/base/server/scripts/operations
+++ b/base/server/scripts/operations
@@ -1352,10 +1352,24 @@ start_instance()
return $rv
fi
+ # Copy pki.policy template
+ /bin/cp /usr/share/pki/server/conf/pki.policy /var/lib/pki/$PKI_INSTANCE_NAME/conf
+
+ # Add permissions for all JAR files in /var/lib/pki/$PKI_INSTANCE_NAME/common/lib
+ for path in /var/lib/pki/$PKI_INSTANCE_NAME/common/lib/*; do
+
+ cat >> /var/lib/pki/$PKI_INSTANCE_NAME/conf/pki.policy << EOF
+
+grant codeBase "file:$(realpath $path)" {
+ permission java.security.AllPermission;
+};
+EOF
+ done
+
# Generate catalina.policy dynamically.
cat /usr/share/pki/server/conf/catalina.policy \
/usr/share/tomcat/conf/catalina.policy \
- /usr/share/pki/server/conf/pki.policy \
+ /var/lib/pki/$PKI_INSTANCE_NAME/conf/pki.policy \
/var/lib/pki/$PKI_INSTANCE_NAME/conf/custom.policy > \
/var/lib/pki/$PKI_INSTANCE_NAME/conf/catalina.policy