You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
bdii.srvice, bdii-slapd.service are uneccessarily exposed and potentially insecure due to elevated roles & permissions required, i.e., requirering as root with runuser requiring all system capabilities
Environment
RedHat 9
5.14.0-427.20.1.el9_4.x86_64
bdii-6.0.3-1.el9.noarch
Description
The bdii and bdii-slapd services have to be run under root, no service set up on a constraint user is possible, e.g.,
Dear @thdesy, thanks for the report!
If you are willing to, or if you already made some local tests and changes, we would welcome a PR regarding this issue.
Short Description of the issue
bdii.srvice, bdii-slapd.service are uneccessarily exposed and potentially insecure due to elevated roles & permissions required, i.e., requirering as root with
runuser
requiring all system capabilitiesEnvironment
Description
The bdii and bdii-slapd services have to be run under root, no service set up on a constraint user is possible, e.g.,
also no dropping of capabilities is possible, e.g.
Presumed cause
The default service seems to reuse a SysV run script, that relies on
runuser
to drop fromroot
to theldap
user.The text was updated successfully, but these errors were encountered: