Blame SOURCES/0038-SUDO-Root-should-be-able-to-read-write-sssd-sudo-soc.patch

cdf651
From 2708fb488277209a60a5daf5217502c029c196c1 Mon Sep 17 00:00:00 2001
cdf651
From: Lukas Slebodnik <lslebodn@redhat.com>
cdf651
Date: Tue, 24 Jul 2018 18:52:08 +0000
cdf651
Subject: [PATCH] SUDO: Root should be able to read/write sssd-sudo socket
cdf651
cdf651
There is not any reason to require additional capabilities from root
cdf651
when sssd is running as unprivileged user.
cdf651
cdf651
Sudo UNIX socket is not a real private socket. It just cannot
cdf651
be used by others. Just owner(sssd) and root should be able to use it.
cdf651
cdf651
Resolves:
cdf651
https://pagure.io/SSSD/sssd/issue/3778
cdf651
cdf651
Merges: https://pagure.io/SSSD/sssd/pull-request/3784
cdf651
cdf651
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com>
cdf651
(cherry picked from commit 21ea8204a0bd8ea4451f420713e909d3cfee34ef)
cdf651
---
cdf651
 src/sysv/systemd/sssd-sudo.socket.in | 3 +--
cdf651
 1 file changed, 1 insertion(+), 2 deletions(-)
cdf651
cdf651
diff --git a/src/sysv/systemd/sssd-sudo.socket.in b/src/sysv/systemd/sssd-sudo.socket.in
cdf651
index 96a8b0327ddb4d331c9b2e97ece3453f8f76872d..e94a2f6151e3d69edc304776b72a81db22762503 100644
cdf651
--- a/src/sysv/systemd/sssd-sudo.socket.in
cdf651
+++ b/src/sysv/systemd/sssd-sudo.socket.in
cdf651
@@ -10,8 +10,7 @@ Conflicts=shutdown.target
cdf651
 ExecStartPre=@libexecdir@/sssd/sssd_check_socket_activated_responders -r sudo
cdf651
 ListenStream=@pipepath@/sudo
cdf651
 SocketUser=@SSSD_USER@
cdf651
-SocketGroup=@SSSD_USER@
cdf651
-SocketMode=0600
cdf651
+SocketMode=0660
cdf651
 
cdf651
 [Install]
cdf651
 WantedBy=sssd.service
cdf651
-- 
cdf651
2.14.4
cdf651