On Sat, Oct 05, 2024 at 10:53:16AM +0300, Alexander Bokovoy wrote:
> Can we move systemd-homed configuration and activation into something
> that could be explicitly enabled by the administrators? Whether this is
> done during installation or post, it still would need to be a concious
> step made by admins.

It can be enabled and disabled. Nevertheless, having it enabled seems
to e a good default. If there are no homed users defined, it should
just hang in the background doing nothing. (Though maybe it could exit
after being started. I'll try to look into this.)

Any SELinux denials will have to be fixed anyway. So this is not an
argument for disabling it.

Zbyszek

> Right now systemd-homed is activated on each system without ask for it,
> even on systems that do not benefit from its use (see parallel
> discussion by Neal). I also see it as a sole contributor to SELinux AVCs
> in OpenQA tests we run for FreeIPA use cases.
-- 
_______________________________________________
devel mailing list -- devel@lists.fedoraproject.org
To unsubscribe send an email to devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to