From 79b90d1465ab408453ed0965ef489d2d994340ba Mon Sep 17 00:00:00 2001 From: Rob Crittenden Date: Mon, 10 Sep 2012 17:07:54 -0400 Subject: Set SELinux default context to unconfined_u:s0-s0:c0.c1023 Don't require ipaselinuxdefaultuser to be set. If this is unset then SSSD will use the system default. https://fedorahosted.org/freeipa/ticket/3045 --- install/updates/50-ipaconfig.update | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'install/updates/50-ipaconfig.update') diff --git a/install/updates/50-ipaconfig.update b/install/updates/50-ipaconfig.update index b08df1806..0992db4ec 100644 --- a/install/updates/50-ipaconfig.update +++ b/install/updates/50-ipaconfig.update @@ -1,5 +1,5 @@ dn: cn=ipaConfig,cn=etc,$SUFFIX add:ipaSELinuxUserMapOrder: guest_u:s0$$xguest_u:s0$$user_u:s0-s0:c0.c1023$$staff_u:s0-s0:c0.c1023$$unconfined_u:s0-s0:c0.c1023 -add:ipaSELinuxUserMapDefault: guest_u:s0 +add:ipaSELinuxUserMapDefault: unconfined_u:s0-s0:c0.c1023 add:ipaUserObjectClasses: ipasshuser -- cgit