Bugzilla – Bug 1144051
Please add "pam_keyinit.so" to the /etc/pam.d/mrsh and /etc/pam.d/mrlogin configuration files
Last modified: 2020-05-28 22:16:00 UTC
In the near future, the use of kernel keyrings will be enabled by systemd. To fully support this feature, the mrsh package must include the pam_keyinit.so module in its /etc/pam.d/mrsh and /etc/pam.d/mrlogin configuration files. Please add this module to the /etc/pam.d/mrsh and /etc/pam.d/mrlogin configuration files with the appropriate parameters: session optional pam_keyinit.so revoke [force] Thanks.
You've opened this for SLE-15 - this product has been released already. Are you saying this feature gets added to a released product? Can you point me to the ECO describing possible side effects as well as risk and risk mitigation?
(In reply to Egbert Eich from comment #1) > You've opened this for SLE-15 - this product has been released already. > Are you saying this feature gets added to a released product? > Can you point me to the ECO describing possible side effects as well as > risk and risk mitigation? Please add it to factory for future releases. I couldn't find the appropriate release.
(In reply to Josef Möllers from comment #2) > (In reply to Egbert Eich from comment #1) > > You've opened this for SLE-15 - this product has been released already. > > Are you saying this feature gets added to a released product? > > Can you point me to the ECO describing possible side effects as well as > > risk and risk mitigation? > > Please add it to factory for future releases. > I couldn't find the appropriate release. Changesd the target to openSUSE factory.
Changed codestream to TW where it belongs.
ping! Any progress?
Since the product is not SLE-15 any more, is there any progress? The systemd folks want to enable keyrings.
Done. SR#754486
This is an autogenerated message for OBS integration: This bug (1144051) was mentioned in https://build.opensuse.org/request/show/754486 Factory / mrsh
Ok, thanks!
SUSE-RU-2020:1259-1: An update that has one recommended fix can now be installed. Category: recommended (moderate) Bug References: 1144051 CVE References: Sources used: SUSE Linux Enterprise Module for HPC 12 (src): mrsh-2.12-6.3.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-RU-2020:1402-1: An update that has one recommended fix can now be installed. Category: recommended (moderate) Bug References: 1144051 CVE References: Sources used: SUSE Linux Enterprise Module for HPC 15-SP1 (src): mrsh-2.12-4.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-RU-2020:0729-1: An update that has one recommended fix can now be installed. Category: recommended (moderate) Bug References: 1144051 CVE References: Sources used: openSUSE Leap 15.1 (src): mrsh-2.12-lp151.4.3.1