Bug 1210951 - AUDIT-WHITELIST: kubernetes1.27: audit of sysctl.d drop-in configuration files for kubeadm binary
Summary: AUDIT-WHITELIST: kubernetes1.27: audit of sysctl.d drop-in configuration file...
Status: RESOLVED FIXED
Alias: None
Product: SUSE Security Incidents
Classification: Novell Products
Component: Audits (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Wolfgang Frisch
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-04-28 10:57 UTC by Priyanka Saggu
Modified: 2023-12-05 13:21 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Priyanka Saggu 2023-04-28 10:57:58 UTC
(copy of a similar previous ticket - https://bugzilla.suse.com/show_bug.cgi?id=1209363)

For my packages found in OBS at openSUSE:Factory:Staging:adi:16/kubernetes1.27 , I would like a whitelisting for the following rpmlint error:

```
[  916s] kubernetes1.25-kubeadm.x86_64: E: sysctl-file-unauthorized (Badness: 10000) /usr/lib/sysctl.d/90-kubeadm.conf (sha256 file digest default filter:1edd91f46e7dee2e0a0eb0553c2b130f2c1f414af0c7af7029ef787209d9f19c shell filter:e2c2ac17097616ee184af9965776f83ad87dcf9e82ada5c8a3ea0f8371813fe8 xml filter:<failed-to-calculate>)
[  916s] Packaging sysctl.d drop-in configuration files requires a review and
[  916s] whitelisting by the SUSE security team. If the package is intended for
[  916s] inclusion in any SUSE product please open a bug report to request review of
[  916s] the package by the security team. Please refer to
[  916s] https://en.opensuse.org/openSUSE:Package_security_guidelines#audit_bugs for
[  916s] more information.
```

Reference links:

[1] kubernetes1.27 -> https://build.opensuse.org/package/live_build_log/openSUSE:Factory:Staging:adi:16/kubernetes1.27/standard/x86_64
Comment 1 Wolfgang Frisch 2023-05-02 07:50:17 UTC
Thank you for opening this AUDIT bug.
We will schedule it in our team shortly.
Comment 2 Wolfgang Frisch 2023-05-03 07:57:09 UTC
https://build.opensuse.org/request/show/1084090
Comment 3 Wolfgang Frisch 2023-07-06 12:35:26 UTC
Accepted
Comment 4 Priyanka Saggu 2023-07-07 09:19:23 UTC
Thanks so much.