configure_opensc_nss_db remediation fix#7046
Closed
mildas wants to merge 1 commit intoComplianceAsCode:masterfrom
Closed
configure_opensc_nss_db remediation fix#7046mildas wants to merge 1 commit intoComplianceAsCode:masterfrom
mildas wants to merge 1 commit intoComplianceAsCode:masterfrom
Conversation
Collaborator
|
Changes identified: Show detailsRule configure_opensc_nss_db: Recommended tests to execute: |
Contributor
|
/retest |
Collaborator
|
this is an infrastructure problem, java exception |
Collaborator
|
@openscap-ci test this please |
Collaborator
Contributor
Author
|
@jan-cerny aha. Yes, it's related. Thanks for noticing, I will close this PR and continue in other pr discussion. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description:
The remediation needs to ensure that
openscis installed because it uses thepkcs11-switchscript from the package and it also needsopenscfor NSS db./usr/bin/pkcs11-switchis the script for switching db. Not the$(/usr/bin/pkcs11-switch)output (the script outputs current NSS db - "opensc", "coolkey", or empty string).Unfortunately, the remediation still might not work as expected on rhel7, because the database switch might require user interaction, see https://bugzilla.redhat.com/show_bug.cgi?id=1719753. It works when no database is set (no user interaction needed). However, when e.g. coolkey is used, then user is propted with: