linux-system-roles / certificate

Role for managing TLS/SSL certificate issuance and renewal

Home Page:https://linux-system-roles.github.io/certificate/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Issuing certs out of /etc/pki/tls/ is not working when selinux is enabled

seocam opened this issue · comments

Currently issuing certs using certmonger provider in any location out of /etc/pki/tls/ is not working when selinux is enforced.

https://fedorapeople.org/groups/linuxsystemroles/logs/linux-system-roles-certificate-pull-linux-system-roles_certificate-3-4c9f24e-centos-7-20200601-115725/artifacts/test.log.html

role recommends to use selinux system role to mitigate issues like this