From e502db4d71c46ee3e6ec6fc189541e7c5f45fc80 Mon Sep 17 00:00:00 2001 From: Sergio Correia Date: Tue, 22 Jul 2025 05:33:14 -0300 Subject: [PATCH] Fix tmpfiles.d configuration related to the cert store Resolves: RHEL-104571 Signed-off-by: Sergio Correia --- keylime.tmpfiles | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/keylime.tmpfiles b/keylime.tmpfiles index e7a12a9..8aa7ecd 100644 --- a/keylime.tmpfiles +++ b/keylime.tmpfiles @@ -1,6 +1,5 @@ d /run/keylime 0700 keylime keylime - -d /var/lib/keylime/tpm_cert_store 0500 keylime keylime - d /var/lib/keylime 0700 keylime keylime - d /etc/keylime 0500 keylime keylime - @@ -11,13 +10,13 @@ d /etc/keylime/tenant.conf.d 0500 keylime keylime - d /etc/keylime/agent.conf.d 0500 keylime keylime - # TPM certificate store. -# Copy the cert store from /usr/share/keylime/cert_store_dir -# to /var/lib/keylime/cert_store_dir. +# Copy the cert store from /usr/share/keylime/tpm_cert_store +# to /var/lib/keylime/tpm_cert_store. # Files inside /var/lib/keylime/tpm_cert_store/ have # 0400 permission and are owned by keylime/keylime, # while /var/lib/keylime/tpm_cert_store/ itself has # permission 0500, also owned by keylime/keylime. -C /var/lib/keylime/tpm_cert_store 0500 keylime keylime - /usr/share/keylime/cert_store_dir +C /var/lib/keylime/tpm_cert_store 0500 keylime keylime - /usr/share/keylime/tpm_cert_store Z /var/lib/keylime/tpm_cert_store 0400 keylime keylime - z /var/lib/keylime/tpm_cert_store 0500 keylime keylime - # Finally, /var/lib/keylime itself has 0700 permission,