diff --git a/keylime.spec b/keylime.spec index f259b43..78360fc 100644 --- a/keylime.spec +++ b/keylime.spec @@ -9,7 +9,7 @@ Name: keylime Version: 7.12.1 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Open source TPM software for Bootstrapping and Maintaining Trust URL: https://github.com/keylime/keylime @@ -421,6 +421,10 @@ fi %license LICENSE %changelog +* Tue Jul 22 2025 Sergio Correia - 7.12.1-7 +- Fix tmpfiles.d configuration related to the cert store + Resolves: RHEL-104572 + * Thu Jul 10 2025 Sergio Correia - 7.12.1-6 - Populate cert_store_dir with tpmfiles.d Resolves: RHEL-76926 diff --git a/keylime.tmpfiles b/keylime.tmpfiles index e7a12a9..8aa7ecd 100644 --- a/keylime.tmpfiles +++ b/keylime.tmpfiles @@ -1,6 +1,5 @@ d /run/keylime 0700 keylime keylime - -d /var/lib/keylime/tpm_cert_store 0500 keylime keylime - d /var/lib/keylime 0700 keylime keylime - d /etc/keylime 0500 keylime keylime - @@ -11,13 +10,13 @@ d /etc/keylime/tenant.conf.d 0500 keylime keylime - d /etc/keylime/agent.conf.d 0500 keylime keylime - # TPM certificate store. -# Copy the cert store from /usr/share/keylime/cert_store_dir -# to /var/lib/keylime/cert_store_dir. +# Copy the cert store from /usr/share/keylime/tpm_cert_store +# to /var/lib/keylime/tpm_cert_store. # Files inside /var/lib/keylime/tpm_cert_store/ have # 0400 permission and are owned by keylime/keylime, # while /var/lib/keylime/tpm_cert_store/ itself has # permission 0500, also owned by keylime/keylime. -C /var/lib/keylime/tpm_cert_store 0500 keylime keylime - /usr/share/keylime/cert_store_dir +C /var/lib/keylime/tpm_cert_store 0500 keylime keylime - /usr/share/keylime/tpm_cert_store Z /var/lib/keylime/tpm_cert_store 0400 keylime keylime - z /var/lib/keylime/tpm_cert_store 0500 keylime keylime - # Finally, /var/lib/keylime itself has 0700 permission,