From dabc477d5239273b26688a7a48061814bafbda7e Mon Sep 17 00:00:00 2001 From: bms8197 Date: Wed, 16 Feb 2022 14:17:54 +0200 Subject: [PATCH] committing changes in /etc made by "-bash" Package changes: --- .etckeeper | 246 +++++---- alternatives/alt-java | 2 +- alternatives/alt-java.1.gz | 2 +- alternatives/java | 2 +- alternatives/java.1.gz | 2 +- alternatives/jjs | 2 +- alternatives/jjs.1.gz | 2 +- alternatives/jre | 2 +- alternatives/jre_1.8.0 | 2 +- alternatives/jre_1.8.0_openjdk | 2 +- alternatives/jre_openjdk | 2 +- alternatives/keytool | 2 +- alternatives/keytool.1.gz | 2 +- alternatives/orbd | 2 +- alternatives/orbd.1.gz | 2 +- alternatives/pack200 | 2 +- alternatives/pack200.1.gz | 2 +- alternatives/policytool | 2 +- alternatives/policytool.1.gz | 2 +- alternatives/rmid | 2 +- alternatives/rmid.1.gz | 2 +- alternatives/rmiregistry | 2 +- alternatives/rmiregistry.1.gz | 2 +- alternatives/servertool | 2 +- alternatives/servertool.1.gz | 2 +- alternatives/tnameserv | 2 +- alternatives/tnameserv.1.gz | 2 +- alternatives/unpack200 | 2 +- alternatives/unpack200.1.gz | 2 +- ansible/ansible.cfg | 495 +----------------- ansible/hosts | 10 +- audit/auditd.conf | 3 +- centos-release | 2 +- centos-release-upstream | 1 - csf/csf.pignore | 1 + dnf/modules.d/python38.module | 5 + dovecot/conf.d/10-auth.conf.rpmnew | 127 +++++ dovecot/conf.d/10-logging.conf.rpmnew | 105 ++++ dovecot/conf.d/10-mail.conf.rpmnew | 12 +- dovecot/conf.d/10-metrics.conf | 74 +++ dovecot/conf.d/10-ssl.conf.rpmnew | 85 +++ dovecot/conf.d/15-mailboxes.conf.rpmnew | 32 +- dovecot/conf.d/20-imap.conf.rpmnew | 11 +- dovecot/conf.d/20-lmtp.conf.rpmnew | 14 + dovecot/conf.d/auth-vpopmail.conf.ext | 17 - dovecot/dovecot.conf.rpmnew | 101 ++++ gssproxy/99-nfs-client.conf | 1 + iproute2/rt_protos | 1 + .../lib/calendars.properties | 0 .../lib/logging.properties | 0 .../lib/security/blacklisted.certs | 0 .../lib/security/cacerts | 0 .../lib/security/java.policy | 0 .../lib/security/java.security | 0 .../lib/security/nss.cfg | 0 .../lib/security/nss.fips.cfg | 0 .../policy/limited/US_export_policy.jar | Bin .../security/policy/limited/local_policy.jar | Bin .../policy/unlimited/US_export_policy.jar | Bin .../policy/unlimited/local_policy.jar | Bin ...conf => kernel-4.18.0-365.el8.x86_64.conf} | 0 libibverbs.d/i40iw.driver | 1 - libibverbs.d/irdma.driver | 1 + logrotate.d/kvm_stat | 11 + logrotate.d/mysql | 1 + mail/spamassassin/v343.pre | 2 +- mock/alma+epel-8-aarch64.cfg | 6 + mock/alma+epel-8-x86_64.cfg | 6 + mock/centos+epel-7-ppc64le.cfg | 6 + mock/centos+epel-7-x86_64.cfg | 6 + mock/centos-stream+epel-8-aarch64.cfg | 7 + mock/centos-stream+epel-8-ppc64le.cfg | 7 + mock/centos-stream+epel-8-x86_64.cfg | 7 + mock/centos-stream+epel-9-aarch64.cfg | 7 + mock/centos-stream+epel-9-ppc64le.cfg | 7 + mock/centos-stream+epel-9-s390x.cfg | 7 + mock/centos-stream+epel-9-x86_64.cfg | 7 + ... => centos-stream+epel-next-8-aarch64.cfg} | 4 +- ... => centos-stream+epel-next-8-ppc64le.cfg} | 4 +- ...g => centos-stream+epel-next-8-x86_64.cfg} | 4 +- ... => centos-stream+epel-next-9-aarch64.cfg} | 3 +- ... => centos-stream+epel-next-9-ppc64le.cfg} | 3 +- ...fg => centos-stream+epel-next-9-s390x.cfg} | 3 +- ...g => centos-stream+epel-next-9-x86_64.cfg} | 3 +- mock/chroot-aliases.cfg | 38 ++ mock/default.cfg.rpmnew | 1 + .../centos+epel-7-aarch64.cfg} | 3 +- .../centos+epel-7-ppc64.cfg} | 3 +- mock/eol/centos+epel-8-aarch64.cfg | 6 + .../centos+epel-8-ppc64le.cfg} | 4 +- mock/eol/centos+epel-8-x86_64.cfg | 6 + mock/{ => eol}/centos-8-aarch64.cfg | 2 +- mock/{ => eol}/centos-8-ppc64le.cfg | 2 +- mock/{ => eol}/centos-8-x86_64.cfg | 2 +- mock/{ => eol}/epelplayground-8-aarch64.cfg | 2 +- mock/{ => eol}/epelplayground-8-ppc64le.cfg | 2 +- mock/{ => eol}/epelplayground-8-x86_64.cfg | 2 +- mock/{ => eol}/fedora-33-aarch64.cfg | 0 mock/{ => eol}/fedora-33-armhfp.cfg | 0 mock/{ => eol}/fedora-33-i386.cfg | 0 mock/{ => eol}/fedora-33-ppc64le.cfg | 0 mock/{ => eol}/fedora-33-s390x.cfg | 0 mock/{ => eol}/fedora-33-x86_64.cfg | 0 mock/{ => eol}/templates/centos-8.tpl | 35 +- mock/{ => eol}/templates/epelplayground-8.tpl | 0 mock/epel-7-ppc64le.cfg | 6 +- mock/epel-7-x86_64.cfg | 6 +- mock/fedora-36-aarch64.cfg | 6 +- mock/fedora-36-armhfp.cfg | 6 +- mock/fedora-36-i386.cfg | 6 +- mock/fedora-36-ppc64le.cfg | 6 +- mock/fedora-36-s390x.cfg | 6 +- mock/fedora-36-x86_64.cfg | 6 +- mock/fedora-37-aarch64.cfg | 1 + mock/fedora-37-armhfp.cfg | 1 + mock/fedora-37-i386.cfg | 1 + mock/fedora-37-ppc64le.cfg | 1 + mock/fedora-37-s390x.cfg | 1 + mock/fedora-37-x86_64.cfg | 1 + mock/navy-8-x86_64.cfg | 4 + ...h64.cfg => oraclelinux+epel-7-aarch64.cfg} | 4 +- ...6_64.cfg => oraclelinux+epel-7-x86_64.cfg} | 4 +- ...h64.cfg => oraclelinux+epel-8-aarch64.cfg} | 4 +- ...6_64.cfg => oraclelinux+epel-8-x86_64.cfg} | 4 +- ...-8-aarch64.cfg => rhel+epel-8-aarch64.cfg} | 2 +- ...-8-ppc64le.cfg => rhel+epel-8-ppc64le.cfg} | 2 +- mock/rhel+epel-8-s390x.cfg | 4 + ...el-8-x86_64.cfg => rhel+epel-8-x86_64.cfg} | 2 +- mock/rhelepel-8-ppc64.cfg | 4 - ...8-aarch64.cfg => rocky+epel-8-aarch64.cfg} | 4 +- ...l-8-x86_64.cfg => rocky+epel-8-x86_64.cfg} | 4 +- mock/templates/almalinux-8.tpl | 2 +- mock/templates/amazonlinux-2.tpl | 2 +- mock/templates/centos-stream-8.tpl | 58 +- mock/templates/centos-stream-9.tpl | 20 + mock/templates/epel-7.tpl | 2 - mock/templates/epel-8.tpl | 27 +- mock/templates/epel-9.tpl | 65 ++- mock/templates/epel-next-8.tpl | 8 +- mock/templates/epel-next-9.tpl | 8 +- mock/templates/fedora-eln.tpl | 2 +- mock/templates/fedora-rawhide.tpl | 2 +- mock/templates/mageia-7.tpl | 2 +- mock/templates/mageia-branched.tpl | 2 +- mock/templates/navy-8.tpl | 82 +++ mock/templates/rocky-8.tpl | 16 +- nfs.conf | 2 + pam.d/crond | 6 +- pki/ca-trust/extracted/java/cacerts | Bin 146170 -> 146170 bytes profile.d/iproute2.sh | 5 - profile.d/which2.sh | 31 +- selinux/targeted/.policy.sha512 | 2 +- selinux/targeted/contexts/files/file_contexts | 25 +- .../targeted/contexts/files/file_contexts.bin | Bin 569096 -> 570152 bytes selinux/targeted/policy/policy.31 | Bin 8770189 -> 8775245 bytes sysconfig/cpupower | 3 + sysconfig/network-scripts/ifup-routes | 14 +- sysconfig/rngd | 3 + vmware-tools/scripts/vmware/network | 115 +++- vmware-tools/tools.conf.example | 101 +++- yum.repos.d/CentOS-Stream-NFV.repo | 17 + yum.repos.d/CentOS-Stream-Sources.repo | 7 + yum.repos.d/epel-next-testing.repo | 30 ++ yum.repos.d/epel-next.repo | 30 ++ yum.repos.d/epel-playground.repo | 30 -- 165 files changed, 1531 insertions(+), 904 deletions(-) delete mode 100644 centos-release-upstream create mode 100644 dnf/modules.d/python38.module create mode 100644 dovecot/conf.d/10-auth.conf.rpmnew create mode 100644 dovecot/conf.d/10-logging.conf.rpmnew create mode 100644 dovecot/conf.d/10-metrics.conf create mode 100644 dovecot/conf.d/10-ssl.conf.rpmnew delete mode 100644 dovecot/conf.d/auth-vpopmail.conf.ext create mode 100644 dovecot/dovecot.conf.rpmnew rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/calendars.properties (100%) rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/logging.properties (100%) rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/security/blacklisted.certs (100%) rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/security/cacerts (100%) rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/security/java.policy (100%) rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/security/java.security (100%) rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/security/nss.cfg (100%) rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/security/nss.fips.cfg (100%) rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/security/policy/limited/US_export_policy.jar (100%) rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/security/policy/limited/local_policy.jar (100%) rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/security/policy/unlimited/US_export_policy.jar (100%) rename java/java-1.8.0-openjdk/{java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 => java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64}/lib/security/policy/unlimited/local_policy.jar (100%) rename ld.so.conf.d/{kernel-4.18.0-348.el8.x86_64.conf => kernel-4.18.0-365.el8.x86_64.conf} (100%) delete mode 100644 libibverbs.d/i40iw.driver create mode 100644 libibverbs.d/irdma.driver create mode 100644 logrotate.d/kvm_stat create mode 100644 mock/alma+epel-8-aarch64.cfg create mode 100644 mock/alma+epel-8-x86_64.cfg create mode 100644 mock/centos+epel-7-ppc64le.cfg create mode 100644 mock/centos+epel-7-x86_64.cfg create mode 100644 mock/centos-stream+epel-8-aarch64.cfg create mode 100644 mock/centos-stream+epel-8-ppc64le.cfg create mode 100644 mock/centos-stream+epel-8-x86_64.cfg create mode 100644 mock/centos-stream+epel-9-aarch64.cfg create mode 100644 mock/centos-stream+epel-9-ppc64le.cfg create mode 100644 mock/centos-stream+epel-9-s390x.cfg create mode 100644 mock/centos-stream+epel-9-x86_64.cfg rename mock/{epel-next-8-aarch64.cfg => centos-stream+epel-next-8-aarch64.cfg} (65%) rename mock/{epel-next-8-ppc64le.cfg => centos-stream+epel-next-8-ppc64le.cfg} (65%) rename mock/{epel-next-8-x86_64.cfg => centos-stream+epel-next-8-x86_64.cfg} (65%) rename mock/{epel-next-9-aarch64.cfg => centos-stream+epel-next-9-aarch64.cfg} (65%) rename mock/{epel-next-9-ppc64le.cfg => centos-stream+epel-next-9-ppc64le.cfg} (65%) rename mock/{epel-next-9-s390x.cfg => centos-stream+epel-next-9-s390x.cfg} (65%) rename mock/{epel-next-9-x86_64.cfg => centos-stream+epel-next-9-x86_64.cfg} (65%) create mode 100644 mock/chroot-aliases.cfg create mode 120000 mock/default.cfg.rpmnew rename mock/{epel-7-aarch64.cfg => eol/centos+epel-7-aarch64.cfg} (60%) rename mock/{epel-7-ppc64.cfg => eol/centos+epel-7-ppc64.cfg} (59%) create mode 100644 mock/eol/centos+epel-8-aarch64.cfg rename mock/{epel-8-ppc64le.cfg => eol/centos+epel-8-ppc64le.cfg} (58%) create mode 100644 mock/eol/centos+epel-8-x86_64.cfg rename mock/{ => eol}/centos-8-aarch64.cfg (77%) rename mock/{ => eol}/centos-8-ppc64le.cfg (77%) rename mock/{ => eol}/centos-8-x86_64.cfg (76%) rename mock/{ => eol}/epelplayground-8-aarch64.cfg (76%) rename mock/{ => eol}/epelplayground-8-ppc64le.cfg (76%) rename mock/{ => eol}/epelplayground-8-x86_64.cfg (76%) rename mock/{ => eol}/fedora-33-aarch64.cfg (100%) rename mock/{ => eol}/fedora-33-armhfp.cfg (100%) rename mock/{ => eol}/fedora-33-i386.cfg (100%) rename mock/{ => eol}/fedora-33-ppc64le.cfg (100%) rename mock/{ => eol}/fedora-33-s390x.cfg (100%) rename mock/{ => eol}/fedora-33-x86_64.cfg (100%) rename mock/{ => eol}/templates/centos-8.tpl (65%) rename mock/{ => eol}/templates/epelplayground-8.tpl (100%) mode change 100644 => 120000 mock/epel-7-ppc64le.cfg mode change 100644 => 120000 mock/epel-7-x86_64.cfg mode change 120000 => 100644 mock/fedora-36-aarch64.cfg mode change 120000 => 100644 mock/fedora-36-armhfp.cfg mode change 120000 => 100644 mock/fedora-36-i386.cfg mode change 120000 => 100644 mock/fedora-36-ppc64le.cfg mode change 120000 => 100644 mock/fedora-36-s390x.cfg mode change 120000 => 100644 mock/fedora-36-x86_64.cfg create mode 120000 mock/fedora-37-aarch64.cfg create mode 120000 mock/fedora-37-armhfp.cfg create mode 120000 mock/fedora-37-i386.cfg create mode 120000 mock/fedora-37-ppc64le.cfg create mode 120000 mock/fedora-37-s390x.cfg create mode 120000 mock/fedora-37-x86_64.cfg create mode 100644 mock/navy-8-x86_64.cfg rename mock/{oraclelinux-epel-7-aarch64.cfg => oraclelinux+epel-7-aarch64.cfg} (58%) rename mock/{oraclelinux-epel-7-x86_64.cfg => oraclelinux+epel-7-x86_64.cfg} (58%) rename mock/{oraclelinux-epel-8-aarch64.cfg => oraclelinux+epel-8-aarch64.cfg} (58%) rename mock/{oraclelinux-epel-8-x86_64.cfg => oraclelinux+epel-8-x86_64.cfg} (58%) rename mock/{rhelepel-8-aarch64.cfg => rhel+epel-8-aarch64.cfg} (53%) rename mock/{rhelepel-8-ppc64le.cfg => rhel+epel-8-ppc64le.cfg} (53%) create mode 100644 mock/rhel+epel-8-s390x.cfg rename mock/{rhelepel-8-x86_64.cfg => rhel+epel-8-x86_64.cfg} (53%) delete mode 100644 mock/rhelepel-8-ppc64.cfg rename mock/{epel-8-aarch64.cfg => rocky+epel-8-aarch64.cfg} (60%) rename mock/{epel-8-x86_64.cfg => rocky+epel-8-x86_64.cfg} (60%) create mode 100644 mock/templates/navy-8.tpl delete mode 100644 profile.d/iproute2.sh create mode 100644 sysconfig/cpupower create mode 100644 sysconfig/rngd create mode 100644 yum.repos.d/CentOS-Stream-NFV.repo create mode 100644 yum.repos.d/epel-next-testing.repo create mode 100644 yum.repos.d/epel-next.repo delete mode 100644 yum.repos.d/epel-playground.repo diff --git a/.etckeeper b/.etckeeper index efb271d..661392f 100755 --- a/.etckeeper +++ b/.etckeeper @@ -241,7 +241,6 @@ maybe chmod 0644 'bashrc' maybe chmod 0644 'bindresvport.blacklist' maybe chmod 0755 'binfmt.d' maybe chmod 0644 'centos-release' -maybe chmod 0644 'centos-release-upstream' maybe chmod 0755 'chkconfig.d' maybe chmod 0644 'chrony.conf' maybe chgrp 'chrony' 'chrony.keys' @@ -293,7 +292,7 @@ maybe chmod 0640 'cockpit/ws-certs.d/0-self-signed.cert' maybe chmod 0644 'colordiffrc' maybe chmod 0755 'containerd' maybe chmod 0644 'containerd/config.toml' -maybe chmod 0700 'cron.d' +maybe chmod 0755 'cron.d' maybe chmod 0644 'cron.d/0hourly' maybe chmod 0644 'cron.d/clamav-unofficial-sigs' maybe chmod 0644 'cron.d/csf-cron' @@ -307,7 +306,7 @@ maybe chmod 0755 'cron.daily/etckeeper' maybe chmod 0755 'cron.daily/logrotate' maybe chmod 0755 'cron.daily/maldet' maybe chmod 0755 'cron.daily/rkhunter' -maybe chmod 0600 'cron.deny' +maybe chmod 0644 'cron.deny' maybe chmod 0755 'cron.hourly' maybe chmod 0755 'cron.hourly/0anacron' maybe chmod 0755 'cron.monthly' @@ -507,6 +506,7 @@ maybe chmod 0644 'dnf/modules.d/php.module' maybe chmod 0640 'dnf/modules.d/postgresql.module' maybe chmod 0644 'dnf/modules.d/python27.module' maybe chmod 0644 'dnf/modules.d/python36.module' +maybe chmod 0640 'dnf/modules.d/python38.module' maybe chmod 0644 'dnf/modules.d/redis.module' maybe chmod 0644 'dnf/modules.d/ruby.module' maybe chmod 0644 'dnf/modules.d/rust-toolset.module' @@ -537,12 +537,16 @@ maybe chmod 0600 'docker/key.json' maybe chmod 0755 'dovecot' maybe chmod 0755 'dovecot/conf.d' maybe chmod 0644 'dovecot/conf.d/10-auth.conf' +maybe chmod 0644 'dovecot/conf.d/10-auth.conf.rpmnew' maybe chmod 0644 'dovecot/conf.d/10-director.conf' maybe chmod 0644 'dovecot/conf.d/10-logging.conf' +maybe chmod 0644 'dovecot/conf.d/10-logging.conf.rpmnew' maybe chmod 0644 'dovecot/conf.d/10-mail.conf' maybe chmod 0644 'dovecot/conf.d/10-mail.conf.rpmnew' maybe chmod 0644 'dovecot/conf.d/10-master.conf' +maybe chmod 0644 'dovecot/conf.d/10-metrics.conf' maybe chmod 0644 'dovecot/conf.d/10-ssl.conf' +maybe chmod 0644 'dovecot/conf.d/10-ssl.conf.rpmnew' maybe chmod 0644 'dovecot/conf.d/15-lda.conf' maybe chmod 0644 'dovecot/conf.d/15-mailboxes.conf' maybe chmod 0644 'dovecot/conf.d/15-mailboxes.conf.rpmnew' @@ -572,7 +576,6 @@ maybe chmod 0644 'dovecot/conf.d/auth-passwdfile.conf.ext' maybe chmod 0644 'dovecot/conf.d/auth-sql.conf.ext' maybe chmod 0644 'dovecot/conf.d/auth-static.conf.ext' maybe chmod 0644 'dovecot/conf.d/auth-system.conf.ext' -maybe chmod 0644 'dovecot/conf.d/auth-vpopmail.conf.ext' maybe chown 'vmail' 'dovecot/dovecot-dict-auth.conf.ext' maybe chgrp 'dovecot' 'dovecot/dovecot-dict-auth.conf.ext' maybe chmod 0640 'dovecot/dovecot-dict-auth.conf.ext' @@ -586,6 +589,7 @@ maybe chown 'vmail' 'dovecot/dovecot-mysql.conf' maybe chgrp 'dovecot' 'dovecot/dovecot-mysql.conf' maybe chmod 0640 'dovecot/dovecot-mysql.conf' maybe chmod 0644 'dovecot/dovecot.conf' +maybe chmod 0644 'dovecot/dovecot.conf.rpmnew' maybe chown 'vmail' 'dovecot/quota-warning.sh' maybe chgrp 'dovecot' 'dovecot/quota-warning.sh' maybe chmod 0750 'dovecot/quota-warning.sh' @@ -968,23 +972,23 @@ maybe chmod 0644 'issue.net' maybe chmod 0644 'issue.rpmnew' maybe chmod 0755 'java' maybe chmod 0755 'java/java-1.8.0-openjdk' -maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64' -maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib' -maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/calendars.properties' -maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/logging.properties' -maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security' -maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/blacklisted.certs' -maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/java.policy' -maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/java.security' -maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/nss.cfg' -maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/nss.fips.cfg' -maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/policy' -maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/policy/limited' -maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/policy/limited/US_export_policy.jar' -maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/policy/limited/local_policy.jar' -maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/policy/unlimited' -maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/policy/unlimited/US_export_policy.jar' -maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/lib/security/policy/unlimited/local_policy.jar' +maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64' +maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib' +maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/calendars.properties' +maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/logging.properties' +maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security' +maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/blacklisted.certs' +maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/java.policy' +maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/java.security' +maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/nss.cfg' +maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/nss.fips.cfg' +maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/policy' +maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/policy/limited' +maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/policy/limited/US_export_policy.jar' +maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/policy/limited/local_policy.jar' +maybe chmod 0755 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/policy/unlimited' +maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/policy/unlimited/US_export_policy.jar' +maybe chmod 0644 'java/java-1.8.0-openjdk/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/lib/security/policy/unlimited/local_policy.jar' maybe chmod 0755 'java/security' maybe chmod 0755 'java/security/security.d' maybe chmod 0755 'jvm' @@ -1008,7 +1012,7 @@ maybe chmod 0644 'ld.so.conf.d/bind-export-x86_64.conf' maybe chmod 0444 'ld.so.conf.d/kernel-4.18.0-193.6.3.el8_2.x86_64.conf' maybe chmod 0444 'ld.so.conf.d/kernel-4.18.0-348.2.1.el8_5.x86_64.conf' maybe chmod 0444 'ld.so.conf.d/kernel-4.18.0-348.7.1.el8_5.x86_64.conf' -maybe chmod 0444 'ld.so.conf.d/kernel-4.18.0-348.el8.x86_64.conf' +maybe chmod 0444 'ld.so.conf.d/kernel-4.18.0-365.el8.x86_64.conf' maybe chmod 0755 'letsencrypt' maybe chown 'setroubleshoot' 'letsencrypt/.updated-options-ssl-apache-conf-digest.txt' maybe chgrp 'setroubleshoot' 'letsencrypt/.updated-options-ssl-apache-conf-digest.txt' @@ -2597,7 +2601,7 @@ maybe chmod 0644 'libibverbs.d/cxgb4.driver' maybe chmod 0644 'libibverbs.d/efa.driver' maybe chmod 0644 'libibverbs.d/hfi1verbs.driver' maybe chmod 0644 'libibverbs.d/hns.driver' -maybe chmod 0644 'libibverbs.d/i40iw.driver' +maybe chmod 0644 'libibverbs.d/irdma.driver' maybe chmod 0644 'libibverbs.d/mlx4.driver' maybe chmod 0644 'libibverbs.d/mlx5.driver' maybe chmod 0644 'libibverbs.d/qedr.driver' @@ -2634,6 +2638,7 @@ maybe chmod 0644 'logrotate.d/fail2ban' maybe chmod 0644 'logrotate.d/firewalld' maybe chmod 0644 'logrotate.d/httpd' maybe chmod 0644 'logrotate.d/iptraf-ng' +maybe chmod 0644 'logrotate.d/kvm_stat' maybe chmod 0644 'logrotate.d/lfd' maybe chmod 0644 'logrotate.d/mysecureshell' maybe chmod 0644 'logrotate.d/mysql' @@ -2829,6 +2834,10 @@ maybe chmod 0644 'mc/sfs.ini' maybe chmod 0644 'mime.types' maybe chmod 0644 'mke2fs.conf' maybe chmod 0755 'mock' +maybe chgrp 'mock' 'mock/alma+epel-8-aarch64.cfg' +maybe chmod 0644 'mock/alma+epel-8-aarch64.cfg' +maybe chgrp 'mock' 'mock/alma+epel-8-x86_64.cfg' +maybe chmod 0644 'mock/alma+epel-8-x86_64.cfg' maybe chgrp 'mock' 'mock/almalinux-8-aarch64.cfg' maybe chmod 0644 'mock/almalinux-8-aarch64.cfg' maybe chgrp 'mock' 'mock/almalinux-8-x86_64.cfg' @@ -2837,6 +2846,10 @@ maybe chgrp 'mock' 'mock/amazonlinux-2-aarch64.cfg' maybe chmod 0644 'mock/amazonlinux-2-aarch64.cfg' maybe chgrp 'mock' 'mock/amazonlinux-2-x86_64.cfg' maybe chmod 0644 'mock/amazonlinux-2-x86_64.cfg' +maybe chgrp 'mock' 'mock/centos+epel-7-ppc64le.cfg' +maybe chmod 0644 'mock/centos+epel-7-ppc64le.cfg' +maybe chgrp 'mock' 'mock/centos+epel-7-x86_64.cfg' +maybe chmod 0644 'mock/centos+epel-7-x86_64.cfg' maybe chgrp 'mock' 'mock/centos-7-aarch64.cfg' maybe chmod 0644 'mock/centos-7-aarch64.cfg' maybe chgrp 'mock' 'mock/centos-7-ppc64.cfg' @@ -2845,12 +2858,34 @@ maybe chgrp 'mock' 'mock/centos-7-ppc64le.cfg' maybe chmod 0644 'mock/centos-7-ppc64le.cfg' maybe chgrp 'mock' 'mock/centos-7-x86_64.cfg' maybe chmod 0644 'mock/centos-7-x86_64.cfg' -maybe chgrp 'mock' 'mock/centos-8-aarch64.cfg' -maybe chmod 0644 'mock/centos-8-aarch64.cfg' -maybe chgrp 'mock' 'mock/centos-8-ppc64le.cfg' -maybe chmod 0644 'mock/centos-8-ppc64le.cfg' -maybe chgrp 'mock' 'mock/centos-8-x86_64.cfg' -maybe chmod 0644 'mock/centos-8-x86_64.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-8-aarch64.cfg' +maybe chmod 0644 'mock/centos-stream+epel-8-aarch64.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-8-ppc64le.cfg' +maybe chmod 0644 'mock/centos-stream+epel-8-ppc64le.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-8-x86_64.cfg' +maybe chmod 0644 'mock/centos-stream+epel-8-x86_64.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-9-aarch64.cfg' +maybe chmod 0644 'mock/centos-stream+epel-9-aarch64.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-9-ppc64le.cfg' +maybe chmod 0644 'mock/centos-stream+epel-9-ppc64le.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-9-s390x.cfg' +maybe chmod 0644 'mock/centos-stream+epel-9-s390x.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-9-x86_64.cfg' +maybe chmod 0644 'mock/centos-stream+epel-9-x86_64.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-next-8-aarch64.cfg' +maybe chmod 0644 'mock/centos-stream+epel-next-8-aarch64.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-next-8-ppc64le.cfg' +maybe chmod 0644 'mock/centos-stream+epel-next-8-ppc64le.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-next-8-x86_64.cfg' +maybe chmod 0644 'mock/centos-stream+epel-next-8-x86_64.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-next-9-aarch64.cfg' +maybe chmod 0644 'mock/centos-stream+epel-next-9-aarch64.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-next-9-ppc64le.cfg' +maybe chmod 0644 'mock/centos-stream+epel-next-9-ppc64le.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-next-9-s390x.cfg' +maybe chmod 0644 'mock/centos-stream+epel-next-9-s390x.cfg' +maybe chgrp 'mock' 'mock/centos-stream+epel-next-9-x86_64.cfg' +maybe chmod 0644 'mock/centos-stream+epel-next-9-x86_64.cfg' maybe chgrp 'mock' 'mock/centos-stream-8-aarch64.cfg' maybe chmod 0644 'mock/centos-stream-8-aarch64.cfg' maybe chgrp 'mock' 'mock/centos-stream-8-ppc64le.cfg' @@ -2865,6 +2900,8 @@ maybe chgrp 'mock' 'mock/centos-stream-9-s390x.cfg' maybe chmod 0644 'mock/centos-stream-9-s390x.cfg' maybe chgrp 'mock' 'mock/centos-stream-9-x86_64.cfg' maybe chmod 0644 'mock/centos-stream-9-x86_64.cfg' +maybe chgrp 'mock' 'mock/chroot-aliases.cfg' +maybe chmod 0644 'mock/chroot-aliases.cfg' maybe chgrp 'mock' 'mock/custom-1-aarch64.cfg' maybe chmod 0644 'mock/custom-1-aarch64.cfg' maybe chgrp 'mock' 'mock/custom-1-armhfp.cfg' @@ -2882,10 +2919,26 @@ maybe chmod 0644 'mock/custom-1-s390x.cfg' maybe chgrp 'mock' 'mock/custom-1-x86_64.cfg' maybe chmod 0644 'mock/custom-1-x86_64.cfg' maybe chmod 0755 'mock/eol' +maybe chgrp 'mock' 'mock/eol/centos+epel-7-aarch64.cfg' +maybe chmod 0644 'mock/eol/centos+epel-7-aarch64.cfg' +maybe chgrp 'mock' 'mock/eol/centos+epel-7-ppc64.cfg' +maybe chmod 0644 'mock/eol/centos+epel-7-ppc64.cfg' +maybe chgrp 'mock' 'mock/eol/centos+epel-8-aarch64.cfg' +maybe chmod 0644 'mock/eol/centos+epel-8-aarch64.cfg' +maybe chgrp 'mock' 'mock/eol/centos+epel-8-ppc64le.cfg' +maybe chmod 0644 'mock/eol/centos+epel-8-ppc64le.cfg' +maybe chgrp 'mock' 'mock/eol/centos+epel-8-x86_64.cfg' +maybe chmod 0644 'mock/eol/centos+epel-8-x86_64.cfg' maybe chgrp 'mock' 'mock/eol/centos-6-i386.cfg' maybe chmod 0644 'mock/eol/centos-6-i386.cfg' maybe chgrp 'mock' 'mock/eol/centos-6-x86_64.cfg' maybe chmod 0644 'mock/eol/centos-6-x86_64.cfg' +maybe chgrp 'mock' 'mock/eol/centos-8-aarch64.cfg' +maybe chmod 0644 'mock/eol/centos-8-aarch64.cfg' +maybe chgrp 'mock' 'mock/eol/centos-8-ppc64le.cfg' +maybe chmod 0644 'mock/eol/centos-8-ppc64le.cfg' +maybe chgrp 'mock' 'mock/eol/centos-8-x86_64.cfg' +maybe chmod 0644 'mock/eol/centos-8-x86_64.cfg' maybe chgrp 'mock' 'mock/eol/epel-5-i386.cfg' maybe chmod 0644 'mock/eol/epel-5-i386.cfg' maybe chgrp 'mock' 'mock/eol/epel-5-x86_64.cfg' @@ -2894,6 +2947,12 @@ maybe chgrp 'mock' 'mock/eol/epel-6-i386.cfg' maybe chmod 0644 'mock/eol/epel-6-i386.cfg' maybe chgrp 'mock' 'mock/eol/epel-6-x86_64.cfg' maybe chmod 0644 'mock/eol/epel-6-x86_64.cfg' +maybe chgrp 'mock' 'mock/eol/epelplayground-8-aarch64.cfg' +maybe chmod 0644 'mock/eol/epelplayground-8-aarch64.cfg' +maybe chgrp 'mock' 'mock/eol/epelplayground-8-ppc64le.cfg' +maybe chmod 0644 'mock/eol/epelplayground-8-ppc64le.cfg' +maybe chgrp 'mock' 'mock/eol/epelplayground-8-x86_64.cfg' +maybe chmod 0644 'mock/eol/epelplayground-8-x86_64.cfg' maybe chgrp 'mock' 'mock/eol/fedora-25-aarch64.cfg' maybe chmod 0644 'mock/eol/fedora-25-aarch64.cfg' maybe chgrp 'mock' 'mock/eol/fedora-25-armhfp.cfg' @@ -2998,6 +3057,18 @@ maybe chgrp 'mock' 'mock/eol/fedora-32-s390x.cfg' maybe chmod 0644 'mock/eol/fedora-32-s390x.cfg' maybe chgrp 'mock' 'mock/eol/fedora-32-x86_64.cfg' maybe chmod 0644 'mock/eol/fedora-32-x86_64.cfg' +maybe chgrp 'mock' 'mock/eol/fedora-33-aarch64.cfg' +maybe chmod 0644 'mock/eol/fedora-33-aarch64.cfg' +maybe chgrp 'mock' 'mock/eol/fedora-33-armhfp.cfg' +maybe chmod 0644 'mock/eol/fedora-33-armhfp.cfg' +maybe chgrp 'mock' 'mock/eol/fedora-33-i386.cfg' +maybe chmod 0644 'mock/eol/fedora-33-i386.cfg' +maybe chgrp 'mock' 'mock/eol/fedora-33-ppc64le.cfg' +maybe chmod 0644 'mock/eol/fedora-33-ppc64le.cfg' +maybe chgrp 'mock' 'mock/eol/fedora-33-s390x.cfg' +maybe chmod 0644 'mock/eol/fedora-33-s390x.cfg' +maybe chgrp 'mock' 'mock/eol/fedora-33-x86_64.cfg' +maybe chmod 0644 'mock/eol/fedora-33-x86_64.cfg' maybe chgrp 'mock' 'mock/eol/mageia-6-armv5tl.cfg' maybe chmod 0644 'mock/eol/mageia-6-armv5tl.cfg' maybe chgrp 'mock' 'mock/eol/mageia-6-armv7hl.cfg' @@ -3027,8 +3098,12 @@ maybe chmod 0644 'mock/eol/rhel-6-x86_64.cfg' maybe chmod 0755 'mock/eol/templates' maybe chgrp 'mock' 'mock/eol/templates/centos-6.tpl' maybe chmod 0644 'mock/eol/templates/centos-6.tpl' +maybe chgrp 'mock' 'mock/eol/templates/centos-8.tpl' +maybe chmod 0644 'mock/eol/templates/centos-8.tpl' maybe chgrp 'mock' 'mock/eol/templates/epel-6.tpl' maybe chmod 0644 'mock/eol/templates/epel-6.tpl' +maybe chgrp 'mock' 'mock/eol/templates/epelplayground-8.tpl' +maybe chmod 0644 'mock/eol/templates/epelplayground-8.tpl' maybe chgrp 'mock' 'mock/eol/templates/fedora-29.tpl' maybe chmod 0644 'mock/eol/templates/fedora-29.tpl' maybe chgrp 'mock' 'mock/eol/templates/fedora-30.tpl' @@ -3039,58 +3114,12 @@ maybe chgrp 'mock' 'mock/eol/templates/openmandriva-4.0.tpl' maybe chmod 0644 'mock/eol/templates/openmandriva-4.0.tpl' maybe chgrp 'mock' 'mock/eol/templates/rhel-6.tpl' maybe chmod 0644 'mock/eol/templates/rhel-6.tpl' -maybe chgrp 'mock' 'mock/epel-7-aarch64.cfg' -maybe chmod 0644 'mock/epel-7-aarch64.cfg' -maybe chgrp 'mock' 'mock/epel-7-ppc64.cfg' -maybe chmod 0644 'mock/epel-7-ppc64.cfg' -maybe chgrp 'mock' 'mock/epel-7-ppc64le.cfg' -maybe chmod 0644 'mock/epel-7-ppc64le.cfg' -maybe chgrp 'mock' 'mock/epel-7-x86_64.cfg' -maybe chmod 0644 'mock/epel-7-x86_64.cfg' -maybe chgrp 'mock' 'mock/epel-8-aarch64.cfg' -maybe chmod 0644 'mock/epel-8-aarch64.cfg' -maybe chgrp 'mock' 'mock/epel-8-ppc64le.cfg' -maybe chmod 0644 'mock/epel-8-ppc64le.cfg' -maybe chgrp 'mock' 'mock/epel-8-x86_64.cfg' -maybe chmod 0644 'mock/epel-8-x86_64.cfg' -maybe chgrp 'mock' 'mock/epel-next-8-aarch64.cfg' -maybe chmod 0644 'mock/epel-next-8-aarch64.cfg' -maybe chgrp 'mock' 'mock/epel-next-8-ppc64le.cfg' -maybe chmod 0644 'mock/epel-next-8-ppc64le.cfg' -maybe chgrp 'mock' 'mock/epel-next-8-x86_64.cfg' -maybe chmod 0644 'mock/epel-next-8-x86_64.cfg' -maybe chgrp 'mock' 'mock/epel-next-9-aarch64.cfg' -maybe chmod 0644 'mock/epel-next-9-aarch64.cfg' -maybe chgrp 'mock' 'mock/epel-next-9-ppc64le.cfg' -maybe chmod 0644 'mock/epel-next-9-ppc64le.cfg' -maybe chgrp 'mock' 'mock/epel-next-9-s390x.cfg' -maybe chmod 0644 'mock/epel-next-9-s390x.cfg' -maybe chgrp 'mock' 'mock/epel-next-9-x86_64.cfg' -maybe chmod 0644 'mock/epel-next-9-x86_64.cfg' -maybe chgrp 'mock' 'mock/epelplayground-8-aarch64.cfg' -maybe chmod 0644 'mock/epelplayground-8-aarch64.cfg' -maybe chgrp 'mock' 'mock/epelplayground-8-ppc64le.cfg' -maybe chmod 0644 'mock/epelplayground-8-ppc64le.cfg' -maybe chgrp 'mock' 'mock/epelplayground-8-x86_64.cfg' -maybe chmod 0644 'mock/epelplayground-8-x86_64.cfg' maybe chgrp 'mock' 'mock/eurolinux-8-aarch64.cfg' maybe chmod 0644 'mock/eurolinux-8-aarch64.cfg' maybe chgrp 'mock' 'mock/eurolinux-8-i686.cfg' maybe chmod 0644 'mock/eurolinux-8-i686.cfg' maybe chgrp 'mock' 'mock/eurolinux-8-x86_64.cfg' maybe chmod 0644 'mock/eurolinux-8-x86_64.cfg' -maybe chgrp 'mock' 'mock/fedora-33-aarch64.cfg' -maybe chmod 0644 'mock/fedora-33-aarch64.cfg' -maybe chgrp 'mock' 'mock/fedora-33-armhfp.cfg' -maybe chmod 0644 'mock/fedora-33-armhfp.cfg' -maybe chgrp 'mock' 'mock/fedora-33-i386.cfg' -maybe chmod 0644 'mock/fedora-33-i386.cfg' -maybe chgrp 'mock' 'mock/fedora-33-ppc64le.cfg' -maybe chmod 0644 'mock/fedora-33-ppc64le.cfg' -maybe chgrp 'mock' 'mock/fedora-33-s390x.cfg' -maybe chmod 0644 'mock/fedora-33-s390x.cfg' -maybe chgrp 'mock' 'mock/fedora-33-x86_64.cfg' -maybe chmod 0644 'mock/fedora-33-x86_64.cfg' maybe chgrp 'mock' 'mock/fedora-34-aarch64.cfg' maybe chmod 0644 'mock/fedora-34-aarch64.cfg' maybe chgrp 'mock' 'mock/fedora-34-armhfp.cfg' @@ -3115,6 +3144,18 @@ maybe chgrp 'mock' 'mock/fedora-35-s390x.cfg' maybe chmod 0644 'mock/fedora-35-s390x.cfg' maybe chgrp 'mock' 'mock/fedora-35-x86_64.cfg' maybe chmod 0644 'mock/fedora-35-x86_64.cfg' +maybe chgrp 'mock' 'mock/fedora-36-aarch64.cfg' +maybe chmod 0644 'mock/fedora-36-aarch64.cfg' +maybe chgrp 'mock' 'mock/fedora-36-armhfp.cfg' +maybe chmod 0644 'mock/fedora-36-armhfp.cfg' +maybe chgrp 'mock' 'mock/fedora-36-i386.cfg' +maybe chmod 0644 'mock/fedora-36-i386.cfg' +maybe chgrp 'mock' 'mock/fedora-36-ppc64le.cfg' +maybe chmod 0644 'mock/fedora-36-ppc64le.cfg' +maybe chgrp 'mock' 'mock/fedora-36-s390x.cfg' +maybe chmod 0644 'mock/fedora-36-s390x.cfg' +maybe chgrp 'mock' 'mock/fedora-36-x86_64.cfg' +maybe chmod 0644 'mock/fedora-36-x86_64.cfg' maybe chgrp 'mock' 'mock/fedora-eln-aarch64.cfg' maybe chmod 0644 'mock/fedora-eln-aarch64.cfg' maybe chgrp 'mock' 'mock/fedora-eln-i386.cfg' @@ -3162,6 +3203,8 @@ maybe chgrp 'mock' 'mock/mageia-cauldron-i586.cfg' maybe chmod 0644 'mock/mageia-cauldron-i586.cfg' maybe chgrp 'mock' 'mock/mageia-cauldron-x86_64.cfg' maybe chmod 0644 'mock/mageia-cauldron-x86_64.cfg' +maybe chgrp 'mock' 'mock/navy-8-x86_64.cfg' +maybe chmod 0644 'mock/navy-8-x86_64.cfg' maybe chgrp 'mock' 'mock/openmandriva-4.1-aarch64.cfg' maybe chmod 0644 'mock/openmandriva-4.1-aarch64.cfg' maybe chgrp 'mock' 'mock/openmandriva-4.1-armv7hnl.cfg' @@ -3210,6 +3253,14 @@ maybe chgrp 'mock' 'mock/opensuse-tumbleweed-s390x.cfg' maybe chmod 0644 'mock/opensuse-tumbleweed-s390x.cfg' maybe chgrp 'mock' 'mock/opensuse-tumbleweed-x86_64.cfg' maybe chmod 0644 'mock/opensuse-tumbleweed-x86_64.cfg' +maybe chgrp 'mock' 'mock/oraclelinux+epel-7-aarch64.cfg' +maybe chmod 0644 'mock/oraclelinux+epel-7-aarch64.cfg' +maybe chgrp 'mock' 'mock/oraclelinux+epel-7-x86_64.cfg' +maybe chmod 0644 'mock/oraclelinux+epel-7-x86_64.cfg' +maybe chgrp 'mock' 'mock/oraclelinux+epel-8-aarch64.cfg' +maybe chmod 0644 'mock/oraclelinux+epel-8-aarch64.cfg' +maybe chgrp 'mock' 'mock/oraclelinux+epel-8-x86_64.cfg' +maybe chmod 0644 'mock/oraclelinux+epel-8-x86_64.cfg' maybe chgrp 'mock' 'mock/oraclelinux-7-aarch64.cfg' maybe chmod 0644 'mock/oraclelinux-7-aarch64.cfg' maybe chgrp 'mock' 'mock/oraclelinux-7-x86_64.cfg' @@ -3218,14 +3269,14 @@ maybe chgrp 'mock' 'mock/oraclelinux-8-aarch64.cfg' maybe chmod 0644 'mock/oraclelinux-8-aarch64.cfg' maybe chgrp 'mock' 'mock/oraclelinux-8-x86_64.cfg' maybe chmod 0644 'mock/oraclelinux-8-x86_64.cfg' -maybe chgrp 'mock' 'mock/oraclelinux-epel-7-aarch64.cfg' -maybe chmod 0644 'mock/oraclelinux-epel-7-aarch64.cfg' -maybe chgrp 'mock' 'mock/oraclelinux-epel-7-x86_64.cfg' -maybe chmod 0644 'mock/oraclelinux-epel-7-x86_64.cfg' -maybe chgrp 'mock' 'mock/oraclelinux-epel-8-aarch64.cfg' -maybe chmod 0644 'mock/oraclelinux-epel-8-aarch64.cfg' -maybe chgrp 'mock' 'mock/oraclelinux-epel-8-x86_64.cfg' -maybe chmod 0644 'mock/oraclelinux-epel-8-x86_64.cfg' +maybe chgrp 'mock' 'mock/rhel+epel-8-aarch64.cfg' +maybe chmod 0644 'mock/rhel+epel-8-aarch64.cfg' +maybe chgrp 'mock' 'mock/rhel+epel-8-ppc64le.cfg' +maybe chmod 0644 'mock/rhel+epel-8-ppc64le.cfg' +maybe chgrp 'mock' 'mock/rhel+epel-8-s390x.cfg' +maybe chmod 0644 'mock/rhel+epel-8-s390x.cfg' +maybe chgrp 'mock' 'mock/rhel+epel-8-x86_64.cfg' +maybe chmod 0644 'mock/rhel+epel-8-x86_64.cfg' maybe chgrp 'mock' 'mock/rhel-7-aarch64.cfg' maybe chmod 0644 'mock/rhel-7-aarch64.cfg' maybe chgrp 'mock' 'mock/rhel-7-ppc64.cfg' @@ -3244,14 +3295,10 @@ maybe chgrp 'mock' 'mock/rhel-8-s390x.cfg' maybe chmod 0644 'mock/rhel-8-s390x.cfg' maybe chgrp 'mock' 'mock/rhel-8-x86_64.cfg' maybe chmod 0644 'mock/rhel-8-x86_64.cfg' -maybe chgrp 'mock' 'mock/rhelepel-8-aarch64.cfg' -maybe chmod 0644 'mock/rhelepel-8-aarch64.cfg' -maybe chgrp 'mock' 'mock/rhelepel-8-ppc64.cfg' -maybe chmod 0644 'mock/rhelepel-8-ppc64.cfg' -maybe chgrp 'mock' 'mock/rhelepel-8-ppc64le.cfg' -maybe chmod 0644 'mock/rhelepel-8-ppc64le.cfg' -maybe chgrp 'mock' 'mock/rhelepel-8-x86_64.cfg' -maybe chmod 0644 'mock/rhelepel-8-x86_64.cfg' +maybe chgrp 'mock' 'mock/rocky+epel-8-aarch64.cfg' +maybe chmod 0644 'mock/rocky+epel-8-aarch64.cfg' +maybe chgrp 'mock' 'mock/rocky+epel-8-x86_64.cfg' +maybe chmod 0644 'mock/rocky+epel-8-x86_64.cfg' maybe chgrp 'mock' 'mock/rocky-8-aarch64.cfg' maybe chmod 0644 'mock/rocky-8-aarch64.cfg' maybe chgrp 'mock' 'mock/rocky-8-x86_64.cfg' @@ -3265,8 +3312,6 @@ maybe chgrp 'mock' 'mock/templates/amazonlinux-2.tpl' maybe chmod 0644 'mock/templates/amazonlinux-2.tpl' maybe chgrp 'mock' 'mock/templates/centos-7.tpl' maybe chmod 0644 'mock/templates/centos-7.tpl' -maybe chgrp 'mock' 'mock/templates/centos-8.tpl' -maybe chmod 0644 'mock/templates/centos-8.tpl' maybe chgrp 'mock' 'mock/templates/centos-stream-8.tpl' maybe chmod 0644 'mock/templates/centos-stream-8.tpl' maybe chgrp 'mock' 'mock/templates/centos-stream-9.tpl' @@ -3283,8 +3328,6 @@ maybe chgrp 'mock' 'mock/templates/epel-next-8.tpl' maybe chmod 0644 'mock/templates/epel-next-8.tpl' maybe chgrp 'mock' 'mock/templates/epel-next-9.tpl' maybe chmod 0644 'mock/templates/epel-next-9.tpl' -maybe chgrp 'mock' 'mock/templates/epelplayground-8.tpl' -maybe chmod 0644 'mock/templates/epelplayground-8.tpl' maybe chgrp 'mock' 'mock/templates/eurolinux-8.tpl' maybe chmod 0644 'mock/templates/eurolinux-8.tpl' maybe chgrp 'mock' 'mock/templates/fedora-branched.tpl' @@ -3299,6 +3342,8 @@ maybe chgrp 'mock' 'mock/templates/mageia-branched.tpl' maybe chmod 0644 'mock/templates/mageia-branched.tpl' maybe chgrp 'mock' 'mock/templates/mageia-cauldron.tpl' maybe chmod 0644 'mock/templates/mageia-cauldron.tpl' +maybe chgrp 'mock' 'mock/templates/navy-8.tpl' +maybe chmod 0644 'mock/templates/navy-8.tpl' maybe chgrp 'mock' 'mock/templates/openmandriva-branched.tpl' maybe chmod 0644 'mock/templates/openmandriva-branched.tpl' maybe chgrp 'mock' 'mock/templates/openmandriva-cooker.tpl' @@ -3844,8 +3889,6 @@ maybe chmod 0644 'nginx/conf.d/mail.club3d.ro.conf' maybe chown 'nginx' 'nginx/conf.d/padmin.club3d.ro.conf' maybe chgrp 'nginx' 'nginx/conf.d/padmin.club3d.ro.conf' maybe chmod 0640 'nginx/conf.d/padmin.club3d.ro.conf' -maybe chown 'nginx' 'nginx/conf.d/php-fpm.conf' -maybe chgrp 'nginx' 'nginx/conf.d/php-fpm.conf' maybe chmod 0644 'nginx/conf.d/php-fpm.conf' maybe chown 'nginx' 'nginx/conf.d/rspamd.club3d.ro.conf' maybe chgrp 'nginx' 'nginx/conf.d/rspamd.club3d.ro.conf' @@ -3877,8 +3920,6 @@ maybe chmod 0640 'nginx/conf.d/zira.898.ro.conf' maybe chown 'nginx' 'nginx/conf.d/zira.go.ro.conf' maybe chgrp 'nginx' 'nginx/conf.d/zira.go.ro.conf' maybe chmod 0644 'nginx/conf.d/zira.go.ro.conf' -maybe chown 'nginx' 'nginx/default.d' -maybe chgrp 'nginx' 'nginx/default.d' maybe chmod 0755 'nginx/default.d' maybe chmod 0644 'nginx/default.d/php.conf' maybe chown 'nginx' 'nginx/fastcgi.conf' @@ -4457,7 +4498,6 @@ maybe chmod 0644 'profile.d/csh.local' maybe chmod 0644 'profile.d/gawk.csh' maybe chmod 0644 'profile.d/gawk.sh' maybe chmod 0640 'profile.d/grc.sh' -maybe chmod 0644 'profile.d/iproute2.sh' maybe chmod 0644 'profile.d/lang.csh' maybe chmod 0644 'profile.d/lang.sh' maybe chmod 0644 'profile.d/less.csh' @@ -4975,6 +5015,7 @@ maybe chmod 0644 'sysconfig/authconfig' maybe chmod 0644 'sysconfig/certbot' maybe chmod 0644 'sysconfig/chronyd' maybe chmod 0755 'sysconfig/console' +maybe chmod 0644 'sysconfig/cpupower' maybe chmod 0644 'sysconfig/crond' maybe chmod 0600 'sysconfig/ebtables-config' maybe chmod 0644 'sysconfig/firewalld' @@ -5040,6 +5081,7 @@ maybe chmod 0755 'sysconfig/rhn/allowed-actions/script' maybe chmod 0755 'sysconfig/rhn/clientCaps.d' maybe chmod 0644 'sysconfig/rhn/up2date' maybe chmod 0640 'sysconfig/rkhunter' +maybe chmod 0644 'sysconfig/rngd' maybe chmod 0644 'sysconfig/rpcbind' maybe chmod 0644 'sysconfig/rsyslog' maybe chmod 0644 'sysconfig/run-parts' @@ -5197,6 +5239,7 @@ maybe chmod 0644 'yum.repos.d/CentOS-Stream-Debuginfo.repo' maybe chmod 0644 'yum.repos.d/CentOS-Stream-Extras.repo' maybe chmod 0644 'yum.repos.d/CentOS-Stream-HighAvailability.repo' maybe chmod 0644 'yum.repos.d/CentOS-Stream-Media.repo' +maybe chmod 0644 'yum.repos.d/CentOS-Stream-NFV.repo' maybe chmod 0644 'yum.repos.d/CentOS-Stream-PowerTools.repo' maybe chmod 0644 'yum.repos.d/CentOS-Stream-RealTime.repo' maybe chmod 0644 'yum.repos.d/CentOS-Stream-ResilientStorage.repo' @@ -5206,7 +5249,8 @@ maybe chmod 0640 'yum.repos.d/bestcrypt.repo' maybe chmod 0640 'yum.repos.d/docker-ce.repo' maybe chmod 0644 'yum.repos.d/elrepo.repo' maybe chmod 0644 'yum.repos.d/epel-modular.repo' -maybe chmod 0644 'yum.repos.d/epel-playground.repo' +maybe chmod 0644 'yum.repos.d/epel-next-testing.repo' +maybe chmod 0644 'yum.repos.d/epel-next.repo' maybe chmod 0644 'yum.repos.d/epel-testing-modular.repo' maybe chmod 0644 'yum.repos.d/epel-testing.repo' maybe chmod 0644 'yum.repos.d/epel.repo' diff --git a/alternatives/alt-java b/alternatives/alt-java index 08c2a2f..a97de37 120000 --- a/alternatives/alt-java +++ b/alternatives/alt-java @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/alt-java \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/alt-java \ No newline at end of file diff --git a/alternatives/alt-java.1.gz b/alternatives/alt-java.1.gz index 25ee7d9..ce6fe80 120000 --- a/alternatives/alt-java.1.gz +++ b/alternatives/alt-java.1.gz @@ -1 +1 @@ -/usr/share/man/man1/alt-java-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/alt-java-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/alternatives/java b/alternatives/java index e937699..4eed62c 120000 --- a/alternatives/java +++ b/alternatives/java @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/java \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/java \ No newline at end of file diff --git a/alternatives/java.1.gz b/alternatives/java.1.gz index 8759baf..cfeedb2 120000 --- a/alternatives/java.1.gz +++ b/alternatives/java.1.gz @@ -1 +1 @@ -/usr/share/man/man1/java-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/java-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/alternatives/jjs b/alternatives/jjs index 8e38c1b..19b639d 120000 --- a/alternatives/jjs +++ b/alternatives/jjs @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/jjs \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/jjs \ No newline at end of file diff --git a/alternatives/jjs.1.gz b/alternatives/jjs.1.gz index 03dae84..e371275 120000 --- a/alternatives/jjs.1.gz +++ b/alternatives/jjs.1.gz @@ -1 +1 @@ -/usr/share/man/man1/jjs-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/jjs-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/alternatives/jre b/alternatives/jre index 765261a..3db9807 120000 --- a/alternatives/jre +++ b/alternatives/jre @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre \ No newline at end of file diff --git a/alternatives/jre_1.8.0 b/alternatives/jre_1.8.0 index 765261a..3db9807 120000 --- a/alternatives/jre_1.8.0 +++ b/alternatives/jre_1.8.0 @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre \ No newline at end of file diff --git a/alternatives/jre_1.8.0_openjdk b/alternatives/jre_1.8.0_openjdk index 5a9fc72..53f2d84 120000 --- a/alternatives/jre_1.8.0_openjdk +++ b/alternatives/jre_1.8.0_openjdk @@ -1 +1 @@ -/usr/lib/jvm/jre-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64 \ No newline at end of file +/usr/lib/jvm/jre-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64 \ No newline at end of file diff --git a/alternatives/jre_openjdk b/alternatives/jre_openjdk index 765261a..3db9807 120000 --- a/alternatives/jre_openjdk +++ b/alternatives/jre_openjdk @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre \ No newline at end of file diff --git a/alternatives/keytool b/alternatives/keytool index dff8672..9be3c75 120000 --- a/alternatives/keytool +++ b/alternatives/keytool @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/keytool \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/keytool \ No newline at end of file diff --git a/alternatives/keytool.1.gz b/alternatives/keytool.1.gz index 1b000ca..2d2c900 120000 --- a/alternatives/keytool.1.gz +++ b/alternatives/keytool.1.gz @@ -1 +1 @@ -/usr/share/man/man1/keytool-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/keytool-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/alternatives/orbd b/alternatives/orbd index b26a842..f22f06e 120000 --- a/alternatives/orbd +++ b/alternatives/orbd @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/orbd \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/orbd \ No newline at end of file diff --git a/alternatives/orbd.1.gz b/alternatives/orbd.1.gz index 7fc0254..e260b02 120000 --- a/alternatives/orbd.1.gz +++ b/alternatives/orbd.1.gz @@ -1 +1 @@ -/usr/share/man/man1/orbd-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/orbd-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/alternatives/pack200 b/alternatives/pack200 index aa04a1c..86178f2 120000 --- a/alternatives/pack200 +++ b/alternatives/pack200 @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/pack200 \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/pack200 \ No newline at end of file diff --git a/alternatives/pack200.1.gz b/alternatives/pack200.1.gz index e772dc1..314081f 120000 --- a/alternatives/pack200.1.gz +++ b/alternatives/pack200.1.gz @@ -1 +1 @@ -/usr/share/man/man1/pack200-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/pack200-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/alternatives/policytool b/alternatives/policytool index 2df507e..730f718 120000 --- a/alternatives/policytool +++ b/alternatives/policytool @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/policytool \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/policytool \ No newline at end of file diff --git a/alternatives/policytool.1.gz b/alternatives/policytool.1.gz index 8762cf0..e7d9e6b 120000 --- a/alternatives/policytool.1.gz +++ b/alternatives/policytool.1.gz @@ -1 +1 @@ -/usr/share/man/man1/policytool-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/policytool-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/alternatives/rmid b/alternatives/rmid index 28bf5b2..99e58e8 120000 --- a/alternatives/rmid +++ b/alternatives/rmid @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/rmid \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/rmid \ No newline at end of file diff --git a/alternatives/rmid.1.gz b/alternatives/rmid.1.gz index c78d388..9371320 120000 --- a/alternatives/rmid.1.gz +++ b/alternatives/rmid.1.gz @@ -1 +1 @@ -/usr/share/man/man1/rmid-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/rmid-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/alternatives/rmiregistry b/alternatives/rmiregistry index fff17ac..e151712 120000 --- a/alternatives/rmiregistry +++ b/alternatives/rmiregistry @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/rmiregistry \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/rmiregistry \ No newline at end of file diff --git a/alternatives/rmiregistry.1.gz b/alternatives/rmiregistry.1.gz index a9f145c..22a6829 120000 --- a/alternatives/rmiregistry.1.gz +++ b/alternatives/rmiregistry.1.gz @@ -1 +1 @@ -/usr/share/man/man1/rmiregistry-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/rmiregistry-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/alternatives/servertool b/alternatives/servertool index 6bf3af7..14f6163 120000 --- a/alternatives/servertool +++ b/alternatives/servertool @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/servertool \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/servertool \ No newline at end of file diff --git a/alternatives/servertool.1.gz b/alternatives/servertool.1.gz index 21e6951..a4b8322 120000 --- a/alternatives/servertool.1.gz +++ b/alternatives/servertool.1.gz @@ -1 +1 @@ -/usr/share/man/man1/servertool-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/servertool-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/alternatives/tnameserv b/alternatives/tnameserv index 324f09c..c58186d 120000 --- a/alternatives/tnameserv +++ b/alternatives/tnameserv @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/tnameserv \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/tnameserv \ No newline at end of file diff --git a/alternatives/tnameserv.1.gz b/alternatives/tnameserv.1.gz index c1e8b20..101b6cd 120000 --- a/alternatives/tnameserv.1.gz +++ b/alternatives/tnameserv.1.gz @@ -1 +1 @@ -/usr/share/man/man1/tnameserv-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/tnameserv-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/alternatives/unpack200 b/alternatives/unpack200 index 7997d2a..6ead4f6 120000 --- a/alternatives/unpack200 +++ b/alternatives/unpack200 @@ -1 +1 @@ -/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64/jre/bin/unpack200 \ No newline at end of file +/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64/jre/bin/unpack200 \ No newline at end of file diff --git a/alternatives/unpack200.1.gz b/alternatives/unpack200.1.gz index 5a4c101..4987f21 120000 --- a/alternatives/unpack200.1.gz +++ b/alternatives/unpack200.1.gz @@ -1 +1 @@ -/usr/share/man/man1/unpack200-java-1.8.0-openjdk-1.8.0.312.b07-2.el8_5.x86_64.1.gz \ No newline at end of file +/usr/share/man/man1/unpack200-java-1.8.0-openjdk-1.8.0.322.b06-2.el8_5.x86_64.1.gz \ No newline at end of file diff --git a/ansible/ansible.cfg b/ansible/ansible.cfg index 2728334..8670215 100644 --- a/ansible/ansible.cfg +++ b/ansible/ansible.cfg @@ -1,490 +1,11 @@ -# config file for ansible -- https://ansible.com/ -# =============================================== - -# nearly all parameters can be overridden in ansible-playbook -# or with command line flags. ansible will read ANSIBLE_CONFIG, -# ansible.cfg in the current working directory, .ansible.cfg in -# the home directory or /etc/ansible/ansible.cfg, whichever it -# finds first - -[defaults] - -# some basic default values... - -#inventory = /etc/ansible/hosts -#library = /usr/share/my_modules/ -#module_utils = /usr/share/my_module_utils/ -#remote_tmp = ~/.ansible/tmp -#local_tmp = ~/.ansible/tmp -#plugin_filters_cfg = /etc/ansible/plugin_filters.yml -#forks = 5 -#poll_interval = 15 -#sudo_user = root -#ask_sudo_pass = True -#ask_pass = True -#transport = smart -#remote_port = 22 -#module_lang = C -#module_set_locale = False - -# plays will gather facts by default, which contain information about -# the remote system. +# Since Ansible 2.12 (core): +# To generate an example config file (a "disabled" one with all default settings, commented out): +# $ ansible-config init --disabled > ansible.cfg # -# smart - gather by default, but don't regather if already gathered -# implicit - gather by default, turn off with gather_facts: False -# explicit - do not gather by default, must say gather_facts: True -#gathering = implicit +# Also you can now have a more complete file by including existing plugins: +# ansible-config init --disabled -t all > ansible.cfg -# This only affects the gathering done by a play's gather_facts directive, -# by default gathering retrieves all facts subsets -# all - gather all subsets -# network - gather min and network facts -# hardware - gather hardware facts (longest facts to retrieve) -# virtual - gather min and virtual facts -# facter - import facts from facter -# ohai - import facts from ohai -# You can combine them using comma (ex: network,virtual) -# You can negate them using ! (ex: !hardware,!facter,!ohai) -# A minimal set of facts is always gathered. -#gather_subset = all +# For previous versions of Ansible you can check for examples in the 'stable' branches of each version +# Note that this file was always incomplete and lagging changes to configuration settings -# some hardware related facts are collected -# with a maximum timeout of 10 seconds. This -# option lets you increase or decrease that -# timeout to something more suitable for the -# environment. -# gather_timeout = 10 - -# Ansible facts are available inside the ansible_facts.* dictionary -# namespace. This setting maintains the behaviour which was the default prior -# to 2.5, duplicating these variables into the main namespace, each with a -# prefix of 'ansible_'. -# This variable is set to True by default for backwards compatibility. It -# will be changed to a default of 'False' in a future release. -# ansible_facts. -# inject_facts_as_vars = True - -# additional paths to search for roles in, colon separated -#roles_path = /etc/ansible/roles - -# uncomment this to disable SSH key host checking -#host_key_checking = False - -# change the default callback, you can only have one 'stdout' type enabled at a time. -#stdout_callback = skippy - - -## Ansible ships with some plugins that require whitelisting, -## this is done to avoid running all of a type by default. -## These setting lists those that you want enabled for your system. -## Custom plugins should not need this unless plugin author specifies it. - -# enable callback plugins, they can output to stdout but cannot be 'stdout' type. -#callback_whitelist = timer, mail - -# Determine whether includes in tasks and handlers are "static" by -# default. As of 2.0, includes are dynamic by default. Setting these -# values to True will make includes behave more like they did in the -# 1.x versions. -#task_includes_static = False -#handler_includes_static = False - -# Controls if a missing handler for a notification event is an error or a warning -#error_on_missing_handler = True - -# change this for alternative sudo implementations -#sudo_exe = sudo - -# What flags to pass to sudo -# WARNING: leaving out the defaults might create unexpected behaviours -#sudo_flags = -H -S -n - -# SSH timeout -#timeout = 10 - -# default user to use for playbooks if user is not specified -# (/usr/bin/ansible will use current user as default) -#remote_user = root - -# logging is off by default unless this path is defined -# if so defined, consider logrotate -#log_path = /var/log/ansible.log - -# default module name for /usr/bin/ansible -#module_name = command - -# use this shell for commands executed under sudo -# you may need to change this to bin/bash in rare instances -# if sudo is constrained -#executable = /bin/sh - -# if inventory variables overlap, does the higher precedence one win -# or are hash values merged together? The default is 'replace' but -# this can also be set to 'merge'. -#hash_behaviour = replace - -# by default, variables from roles will be visible in the global variable -# scope. To prevent this, the following option can be enabled, and only -# tasks and handlers within the role will see the variables there -#private_role_vars = yes - -# list any Jinja2 extensions to enable here: -#jinja2_extensions = jinja2.ext.do,jinja2.ext.i18n - -# if set, always use this private key file for authentication, same as -# if passing --private-key to ansible or ansible-playbook -#private_key_file = /path/to/file - -# If set, configures the path to the Vault password file as an alternative to -# specifying --vault-password-file on the command line. -#vault_password_file = /path/to/vault_password_file - -# format of string {{ ansible_managed }} available within Jinja2 -# templates indicates to users editing templates files will be replaced. -# replacing {file}, {host} and {uid} and strftime codes with proper values. -#ansible_managed = Ansible managed: {file} modified on %Y-%m-%d %H:%M:%S by {uid} on {host} -# {file}, {host}, {uid}, and the timestamp can all interfere with idempotence -# in some situations so the default is a static string: -#ansible_managed = Ansible managed - -# by default, ansible-playbook will display "Skipping [host]" if it determines a task -# should not be run on a host. Set this to "False" if you don't want to see these "Skipping" -# messages. NOTE: the task header will still be shown regardless of whether or not the -# task is skipped. -#display_skipped_hosts = True - -# by default, if a task in a playbook does not include a name: field then -# ansible-playbook will construct a header that includes the task's action but -# not the task's args. This is a security feature because ansible cannot know -# if the *module* considers an argument to be no_log at the time that the -# header is printed. If your environment doesn't have a problem securing -# stdout from ansible-playbook (or you have manually specified no_log in your -# playbook on all of the tasks where you have secret information) then you can -# safely set this to True to get more informative messages. -#display_args_to_stdout = False - -# by default (as of 1.3), Ansible will raise errors when attempting to dereference -# Jinja2 variables that are not set in templates or action lines. Uncomment this line -# to revert the behavior to pre-1.3. -#error_on_undefined_vars = False - -# by default (as of 1.6), Ansible may display warnings based on the configuration of the -# system running ansible itself. This may include warnings about 3rd party packages or -# other conditions that should be resolved if possible. -# to disable these warnings, set the following value to False: -#system_warnings = True - -# by default (as of 1.4), Ansible may display deprecation warnings for language -# features that should no longer be used and will be removed in future versions. -# to disable these warnings, set the following value to False: -#deprecation_warnings = True - -# (as of 1.8), Ansible can optionally warn when usage of the shell and -# command module appear to be simplified by using a default Ansible module -# instead. These warnings can be silenced by adjusting the following -# setting or adding warn=yes or warn=no to the end of the command line -# parameter string. This will for example suggest using the git module -# instead of shelling out to the git command. -# command_warnings = False - - -# set plugin path directories here, separate with colons -#action_plugins = /usr/share/ansible/plugins/action -#become_plugins = /usr/share/ansible/plugins/become -#cache_plugins = /usr/share/ansible/plugins/cache -#callback_plugins = /usr/share/ansible/plugins/callback -#connection_plugins = /usr/share/ansible/plugins/connection -#lookup_plugins = /usr/share/ansible/plugins/lookup -#inventory_plugins = /usr/share/ansible/plugins/inventory -#vars_plugins = /usr/share/ansible/plugins/vars -#filter_plugins = /usr/share/ansible/plugins/filter -#test_plugins = /usr/share/ansible/plugins/test -#terminal_plugins = /usr/share/ansible/plugins/terminal -#strategy_plugins = /usr/share/ansible/plugins/strategy - - -# by default, ansible will use the 'linear' strategy but you may want to try -# another one -#strategy = free - -# by default callbacks are not loaded for /bin/ansible, enable this if you -# want, for example, a notification or logging callback to also apply to -# /bin/ansible runs -#bin_ansible_callbacks = False - - -# don't like cows? that's unfortunate. -# set to 1 if you don't want cowsay support or export ANSIBLE_NOCOWS=1 -#nocows = 1 - -# set which cowsay stencil you'd like to use by default. When set to 'random', -# a random stencil will be selected for each task. The selection will be filtered -# against the `cow_whitelist` option below. -#cow_selection = default -#cow_selection = random - -# when using the 'random' option for cowsay, stencils will be restricted to this list. -# it should be formatted as a comma-separated list with no spaces between names. -# NOTE: line continuations here are for formatting purposes only, as the INI parser -# in python does not support them. -#cow_whitelist=bud-frogs,bunny,cheese,daemon,default,dragon,elephant-in-snake,elephant,eyes,\ -# hellokitty,kitty,luke-koala,meow,milk,moofasa,moose,ren,sheep,small,stegosaurus,\ -# stimpy,supermilker,three-eyes,turkey,turtle,tux,udder,vader-koala,vader,www - -# don't like colors either? -# set to 1 if you don't want colors, or export ANSIBLE_NOCOLOR=1 -#nocolor = 1 - -# if set to a persistent type (not 'memory', for example 'redis') fact values -# from previous runs in Ansible will be stored. This may be useful when -# wanting to use, for example, IP information from one group of servers -# without having to talk to them in the same playbook run to get their -# current IP information. -#fact_caching = memory - -#This option tells Ansible where to cache facts. The value is plugin dependent. -#For the jsonfile plugin, it should be a path to a local directory. -#For the redis plugin, the value is a host:port:database triplet: fact_caching_connection = localhost:6379:0 - -#fact_caching_connection=/tmp - - - -# retry files -# When a playbook fails a .retry file can be created that will be placed in ~/ -# You can enable this feature by setting retry_files_enabled to True -# and you can change the location of the files by setting retry_files_save_path - -#retry_files_enabled = False -#retry_files_save_path = ~/.ansible-retry - -# squash actions -# Ansible can optimise actions that call modules with list parameters -# when looping. Instead of calling the module once per with_ item, the -# module is called once with all items at once. Currently this only works -# under limited circumstances, and only with parameters named 'name'. -#squash_actions = apk,apt,dnf,homebrew,pacman,pkgng,yum,zypper - -# prevents logging of task data, off by default -#no_log = False - -# prevents logging of tasks, but only on the targets, data is still logged on the master/controller -#no_target_syslog = False - -# controls whether Ansible will raise an error or warning if a task has no -# choice but to create world readable temporary files to execute a module on -# the remote machine. This option is False by default for security. Users may -# turn this on to have behaviour more like Ansible prior to 2.1.x. See -# https://docs.ansible.com/ansible/become.html#becoming-an-unprivileged-user -# for more secure ways to fix this than enabling this option. -#allow_world_readable_tmpfiles = False - -# controls the compression level of variables sent to -# worker processes. At the default of 0, no compression -# is used. This value must be an integer from 0 to 9. -#var_compression_level = 9 - -# controls what compression method is used for new-style ansible modules when -# they are sent to the remote system. The compression types depend on having -# support compiled into both the controller's python and the client's python. -# The names should match with the python Zipfile compression types: -# * ZIP_STORED (no compression. available everywhere) -# * ZIP_DEFLATED (uses zlib, the default) -# These values may be set per host via the ansible_module_compression inventory -# variable -#module_compression = 'ZIP_DEFLATED' - -# This controls the cutoff point (in bytes) on --diff for files -# set to 0 for unlimited (RAM may suffer!). -#max_diff_size = 1048576 - -# This controls how ansible handles multiple --tags and --skip-tags arguments -# on the CLI. If this is True then multiple arguments are merged together. If -# it is False, then the last specified argument is used and the others are ignored. -# This option will be removed in 2.8. -#merge_multiple_cli_flags = True - -# Controls showing custom stats at the end, off by default -#show_custom_stats = True - -# Controls which files to ignore when using a directory as inventory with -# possibly multiple sources (both static and dynamic) -#inventory_ignore_extensions = ~, .orig, .bak, .ini, .cfg, .retry, .pyc, .pyo - -# This family of modules use an alternative execution path optimized for network appliances -# only update this setting if you know how this works, otherwise it can break module execution -#network_group_modules=eos, nxos, ios, iosxr, junos, vyos - -# When enabled, this option allows lookups (via variables like {{lookup('foo')}} or when used as -# a loop with `with_foo`) to return data that is not marked "unsafe". This means the data may contain -# jinja2 templating language which will be run through the templating engine. -# ENABLING THIS COULD BE A SECURITY RISK -#allow_unsafe_lookups = False - -# set default errors for all plays -#any_errors_fatal = False - -[inventory] -# enable inventory plugins, default: 'host_list', 'script', 'auto', 'yaml', 'ini', 'toml' -#enable_plugins = host_list, virtualbox, yaml, constructed - -# ignore these extensions when parsing a directory as inventory source -#ignore_extensions = .pyc, .pyo, .swp, .bak, ~, .rpm, .md, .txt, ~, .orig, .ini, .cfg, .retry - -# ignore files matching these patterns when parsing a directory as inventory source -#ignore_patterns= - -# If 'true' unparsed inventory sources become fatal errors, they are warnings otherwise. -#unparsed_is_failed=False - -[privilege_escalation] -#become=True -#become_method=sudo -#become_user=root -#become_ask_pass=False - -[paramiko_connection] - -# uncomment this line to cause the paramiko connection plugin to not record new host -# keys encountered. Increases performance on new host additions. Setting works independently of the -# host key checking setting above. -#record_host_keys=False - -# by default, Ansible requests a pseudo-terminal for commands executed under sudo. Uncomment this -# line to disable this behaviour. -#pty=False - -# paramiko will default to looking for SSH keys initially when trying to -# authenticate to remote devices. This is a problem for some network devices -# that close the connection after a key failure. Uncomment this line to -# disable the Paramiko look for keys function -#look_for_keys = False - -# When using persistent connections with Paramiko, the connection runs in a -# background process. If the host doesn't already have a valid SSH key, by -# default Ansible will prompt to add the host key. This will cause connections -# running in background processes to fail. Uncomment this line to have -# Paramiko automatically add host keys. -#host_key_auto_add = True - -[ssh_connection] - -# ssh arguments to use -# Leaving off ControlPersist will result in poor performance, so use -# paramiko on older platforms rather than removing it, -C controls compression use -#ssh_args = -C -o ControlMaster=auto -o ControlPersist=60s - -# The base directory for the ControlPath sockets. -# This is the "%(directory)s" in the control_path option -# -# Example: -# control_path_dir = /tmp/.ansible/cp -#control_path_dir = ~/.ansible/cp - -# The path to use for the ControlPath sockets. This defaults to a hashed string of the hostname, -# port and username (empty string in the config). The hash mitigates a common problem users -# found with long hostnames and the conventional %(directory)s/ansible-ssh-%%h-%%p-%%r format. -# In those cases, a "too long for Unix domain socket" ssh error would occur. -# -# Example: -# control_path = %(directory)s/%%h-%%r -#control_path = - -# Enabling pipelining reduces the number of SSH operations required to -# execute a module on the remote server. This can result in a significant -# performance improvement when enabled, however when using "sudo:" you must -# first disable 'requiretty' in /etc/sudoers -# -# By default, this option is disabled to preserve compatibility with -# sudoers configurations that have requiretty (the default on many distros). -# -#pipelining = False - -# Control the mechanism for transferring files (old) -# * smart = try sftp and then try scp [default] -# * True = use scp only -# * False = use sftp only -#scp_if_ssh = smart - -# Control the mechanism for transferring files (new) -# If set, this will override the scp_if_ssh option -# * sftp = use sftp to transfer files -# * scp = use scp to transfer files -# * piped = use 'dd' over SSH to transfer files -# * smart = try sftp, scp, and piped, in that order [default] -#transfer_method = smart - -# if False, sftp will not use batch mode to transfer files. This may cause some -# types of file transfer failures impossible to catch however, and should -# only be disabled if your sftp version has problems with batch mode -#sftp_batch_mode = False - -# The -tt argument is passed to ssh when pipelining is not enabled because sudo -# requires a tty by default. -#usetty = True - -# Number of times to retry an SSH connection to a host, in case of UNREACHABLE. -# For each retry attempt, there is an exponential backoff, -# so after the first attempt there is 1s wait, then 2s, 4s etc. up to 30s (max). -#retries = 3 - -[persistent_connection] - -# Configures the persistent connection timeout value in seconds. This value is -# how long the persistent connection will remain idle before it is destroyed. -# If the connection doesn't receive a request before the timeout value -# expires, the connection is shutdown. The default value is 30 seconds. -#connect_timeout = 30 - -# The command timeout value defines the amount of time to wait for a command -# or RPC call before timing out. The value for the command timeout must -# be less than the value of the persistent connection idle timeout (connect_timeout) -# The default value is 30 second. -#command_timeout = 30 - -[accelerate] -#accelerate_port = 5099 -#accelerate_timeout = 30 -#accelerate_connect_timeout = 5.0 - -# The daemon timeout is measured in minutes. This time is measured -# from the last activity to the accelerate daemon. -#accelerate_daemon_timeout = 30 - -# If set to yes, accelerate_multi_key will allow multiple -# private keys to be uploaded to it, though each user must -# have access to the system via SSH to add a new key. The default -# is "no". -#accelerate_multi_key = yes - -[selinux] -# file systems that require special treatment when dealing with security context -# the default behaviour that copies the existing context or uses the user default -# needs to be changed to use the file system dependent context. -#special_context_filesystems=nfs,vboxsf,fuse,ramfs,9p,vfat - -# Set this to yes to allow libvirt_lxc connections to work without SELinux. -#libvirt_lxc_noseclabel = yes - -[colors] -#highlight = white -#verbose = blue -#warn = bright purple -#error = red -#debug = dark gray -#deprecate = purple -#skip = cyan -#unreachable = red -#ok = green -#changed = yellow -#diff_add = green -#diff_remove = red -#diff_lines = cyan - - -[diff] -# Always print diff when running ( same as always running with -D/--diff ) -# always = no - -# Set how many context lines to show in diff -# context = 3 +# for example, for 2.9: https://github.com/ansible/ansible/blob/stable-2.9/examples/ansible.cfg diff --git a/ansible/hosts b/ansible/hosts index 841f4bc..e84a30c 100644 --- a/ansible/hosts +++ b/ansible/hosts @@ -8,14 +8,14 @@ # - You can enter hostnames or ip addresses # - A hostname/ip can be a member of multiple groups -# Ex 1: Ungrouped hosts, specify before any group headers. +# Ex 1: Ungrouped hosts, specify before any group headers: ## green.example.com ## blue.example.com ## 192.168.100.1 ## 192.168.100.10 -# Ex 2: A collection of hosts belonging to the 'webservers' group +# Ex 2: A collection of hosts belonging to the 'webservers' group: ## [webservers] ## alpha.example.org @@ -23,15 +23,15 @@ ## 192.168.1.100 ## 192.168.1.110 -# If you have multiple hosts following a pattern you can specify +# If you have multiple hosts following a pattern, you can specify # them like this: ## www[001:006].example.com -# Ex 3: A collection of database servers in the 'dbservers' group +# Ex 3: A collection of database servers in the 'dbservers' group: ## [dbservers] -## +## ## db01.intranet.mydomain.net ## db02.intranet.mydomain.net ## 10.25.1.56 diff --git a/audit/auditd.conf b/audit/auditd.conf index ff6a335..04da87d 100644 --- a/audit/auditd.conf +++ b/audit/auditd.conf @@ -33,7 +33,8 @@ transport = TCP krb5_principal = auditd ##krb5_key_file = /etc/audit/audit.key distribute_network = no -q_depth = 400 +q_depth = 1200 overflow_action = SYSLOG max_restarts = 10 plugin_dir = /etc/audit/plugins.d +end_of_event_timeout = 2 diff --git a/centos-release b/centos-release index 6e4cd8b..c1171d1 100644 --- a/centos-release +++ b/centos-release @@ -1 +1 @@ -CentOS Linux release 8.5.2111 +CentOS Stream release 8 diff --git a/centos-release-upstream b/centos-release-upstream deleted file mode 100644 index 80cdbe5..0000000 --- a/centos-release-upstream +++ /dev/null @@ -1 +0,0 @@ -Derived from Red Hat Enterprise Linux 8.5 diff --git a/csf/csf.pignore b/csf/csf.pignore index b752ab1..1b9faef 100644 --- a/csf/csf.pignore +++ b/csf/csf.pignore @@ -134,6 +134,7 @@ exe:/usr/bin/monitorix exe:/opt/gitlab/embedded/postgresql/10/bin/postgres exe:/usr/bin/newrelic-infra-service exe:/usr/bin/terraform +exe:/usr/sbin/rngd # ipsec exe:/usr/sbin/xl2tpd diff --git a/dnf/modules.d/python38.module b/dnf/modules.d/python38.module new file mode 100644 index 0000000..0022928 --- /dev/null +++ b/dnf/modules.d/python38.module @@ -0,0 +1,5 @@ +[python38] +name=python38 +stream=3.8 +profiles= +state=enabled diff --git a/dovecot/conf.d/10-auth.conf.rpmnew b/dovecot/conf.d/10-auth.conf.rpmnew new file mode 100644 index 0000000..3e9c4e4 --- /dev/null +++ b/dovecot/conf.d/10-auth.conf.rpmnew @@ -0,0 +1,127 @@ +## +## Authentication processes +## + +# Disable LOGIN command and all other plaintext authentications unless +# SSL/TLS is used (LOGINDISABLED capability). Note that if the remote IP +# matches the local IP (ie. you're connecting from the same computer), the +# connection is considered secure and plaintext authentication is allowed. +# See also ssl=required setting. +#disable_plaintext_auth = yes + +# Authentication cache size (e.g. 10M). 0 means it's disabled. Note that +# bsdauth and PAM require cache_key to be set for caching to be used. +#auth_cache_size = 0 +# Time to live for cached data. After TTL expires the cached record is no +# longer used, *except* if the main database lookup returns internal failure. +# We also try to handle password changes automatically: If user's previous +# authentication was successful, but this one wasn't, the cache isn't used. +# For now this works only with plaintext authentication. +#auth_cache_ttl = 1 hour +# TTL for negative hits (user not found, password mismatch). +# 0 disables caching them completely. +#auth_cache_negative_ttl = 1 hour + +# Space separated list of realms for SASL authentication mechanisms that need +# them. You can leave it empty if you don't want to support multiple realms. +# Many clients simply use the first one listed here, so keep the default realm +# first. +#auth_realms = + +# Default realm/domain to use if none was specified. This is used for both +# SASL realms and appending @domain to username in plaintext logins. +#auth_default_realm = + +# List of allowed characters in username. If the user-given username contains +# a character not listed in here, the login automatically fails. This is just +# an extra check to make sure user can't exploit any potential quote escaping +# vulnerabilities with SQL/LDAP databases. If you want to allow all characters, +# set this value to empty. +#auth_username_chars = abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ01234567890.-_@ + +# Username character translations before it's looked up from databases. The +# value contains series of from -> to characters. For example "#@/@" means +# that '#' and '/' characters are translated to '@'. +#auth_username_translation = + +# Username formatting before it's looked up from databases. You can use +# the standard variables here, eg. %Lu would lowercase the username, %n would +# drop away the domain if it was given, or "%n-AT-%d" would change the '@' into +# "-AT-". This translation is done after auth_username_translation changes. +#auth_username_format = %Lu + +# If you want to allow master users to log in by specifying the master +# username within the normal username string (ie. not using SASL mechanism's +# support for it), you can specify the separator character here. The format +# is then . UW-IMAP uses "*" as the +# separator, so that could be a good choice. +#auth_master_user_separator = + +# Username to use for users logging in with ANONYMOUS SASL mechanism +#auth_anonymous_username = anonymous + +# Maximum number of dovecot-auth worker processes. They're used to execute +# blocking passdb and userdb queries (eg. MySQL and PAM). They're +# automatically created and destroyed as needed. +#auth_worker_max_count = 30 + +# Host name to use in GSSAPI principal names. The default is to use the +# name returned by gethostname(). Use "$ALL" (with quotes) to allow all keytab +# entries. +#auth_gssapi_hostname = + +# Kerberos keytab to use for the GSSAPI mechanism. Will use the system +# default (usually /etc/krb5.keytab) if not specified. You may need to change +# the auth service to run as root to be able to read this file. +#auth_krb5_keytab = + +# Do NTLM and GSS-SPNEGO authentication using Samba's winbind daemon and +# ntlm_auth helper. +#auth_use_winbind = no + +# Path for Samba's ntlm_auth helper binary. +#auth_winbind_helper_path = /usr/bin/ntlm_auth + +# Time to delay before replying to failed authentications. +#auth_failure_delay = 2 secs + +# Require a valid SSL client certificate or the authentication fails. +#auth_ssl_require_client_cert = no + +# Take the username from client's SSL certificate, using +# X509_NAME_get_text_by_NID() which returns the subject's DN's +# CommonName. +#auth_ssl_username_from_cert = no + +# Space separated list of wanted authentication mechanisms: +# plain login digest-md5 cram-md5 ntlm rpa apop anonymous gssapi otp +# gss-spnego +# NOTE: See also disable_plaintext_auth setting. +auth_mechanisms = plain + +## +## Password and user databases +## + +# +# Password database is used to verify user's password (and nothing more). +# You can have multiple passdbs and userdbs. This is useful if you want to +# allow both system users (/etc/passwd) and virtual users to login without +# duplicating the system users into virtual database. +# +# +# +# User database specifies where mails are located and what user/group IDs +# own them. For single-UID configuration use "static" userdb. +# +# + +#!include auth-deny.conf.ext +#!include auth-master.conf.ext + +!include auth-system.conf.ext +#!include auth-sql.conf.ext +#!include auth-ldap.conf.ext +#!include auth-passwdfile.conf.ext +#!include auth-checkpassword.conf.ext +#!include auth-static.conf.ext diff --git a/dovecot/conf.d/10-logging.conf.rpmnew b/dovecot/conf.d/10-logging.conf.rpmnew new file mode 100644 index 0000000..beb15ba --- /dev/null +++ b/dovecot/conf.d/10-logging.conf.rpmnew @@ -0,0 +1,105 @@ +## +## Log destination. +## + +# Log file to use for error messages. "syslog" logs to syslog, +# /dev/stderr logs to stderr. +#log_path = syslog + +# Log file to use for informational messages. Defaults to log_path. +#info_log_path = +# Log file to use for debug messages. Defaults to info_log_path. +#debug_log_path = + +# Syslog facility to use if you're logging to syslog. Usually if you don't +# want to use "mail", you'll use local0..local7. Also other standard +# facilities are supported. +#syslog_facility = mail + +## +## Logging verbosity and debugging. +## + +# Log filter is a space-separated list conditions. If any of the conditions +# match, the log filter matches (i.e. they're ORed together). Parenthesis +# are supported if multiple conditions need to be matched together. +# +# See https://doc.dovecot.org/configuration_manual/event_filter/ for details. +# +# For example: event=http_request_* AND category=error AND category=storage +# +# Filter to specify what debug logging to enable. This will eventually replace +# mail_debug and auth_debug settings. +#log_debug = + +# Crash after logging a matching event. For example category=error will crash +# any time an error is logged, which can be useful for debugging. +#log_core_filter = + +# Log unsuccessful authentication attempts and the reasons why they failed. +#auth_verbose = no + +# In case of password mismatches, log the attempted password. Valid values are +# no, plain and sha1. sha1 can be useful for detecting brute force password +# attempts vs. user simply trying the same password over and over again. +# You can also truncate the value to n chars by appending ":n" (e.g. sha1:6). +#auth_verbose_passwords = no + +# Even more verbose logging for debugging purposes. Shows for example SQL +# queries. +#auth_debug = no + +# In case of password mismatches, log the passwords and used scheme so the +# problem can be debugged. Enabling this also enables auth_debug. +#auth_debug_passwords = no + +# Enable mail process debugging. This can help you figure out why Dovecot +# isn't finding your mails. +#mail_debug = no + +# Show protocol level SSL errors. +#verbose_ssl = no + +# mail_log plugin provides more event logging for mail processes. +plugin { + # Events to log. Also available: flag_change append + #mail_log_events = delete undelete expunge copy mailbox_delete mailbox_rename + # Available fields: uid, box, msgid, from, subject, size, vsize, flags + # size and vsize are available only for expunge and copy events. + #mail_log_fields = uid box msgid size +} + +## +## Log formatting. +## + +# Prefix for each line written to log file. % codes are in strftime(3) +# format. +#log_timestamp = "%b %d %H:%M:%S " + +# Space-separated list of elements we want to log. The elements which have +# a non-empty variable value are joined together to form a comma-separated +# string. +#login_log_format_elements = user=<%u> method=%m rip=%r lip=%l mpid=%e %c + +# Login log format. %s contains login_log_format_elements string, %$ contains +# the data we want to log. +#login_log_format = %$: %s + +# Log prefix for mail processes. See doc/wiki/Variables.txt for list of +# possible variables you can use. +#mail_log_prefix = "%s(%u)<%{pid}><%{session}>: " + +# Format to use for logging mail deliveries: +# %$ - Delivery status message (e.g. "saved to INBOX") +# %m / %{msgid} - Message-ID +# %s / %{subject} - Subject +# %f / %{from} - From address +# %p / %{size} - Physical size +# %w / %{vsize} - Virtual size +# %e / %{from_envelope} - MAIL FROM envelope +# %{to_envelope} - RCPT TO envelope +# %{delivery_time} - How many milliseconds it took to deliver the mail +# %{session_time} - How long LMTP session took, not including delivery_time +# %{storage_id} - Backend-specific ID for mail, e.g. Maildir filename +#deliver_log_format = msgid=%m: %$ diff --git a/dovecot/conf.d/10-mail.conf.rpmnew b/dovecot/conf.d/10-mail.conf.rpmnew index 35e98a7..fee4802 100644 --- a/dovecot/conf.d/10-mail.conf.rpmnew +++ b/dovecot/conf.d/10-mail.conf.rpmnew @@ -165,7 +165,10 @@ namespace inbox { # methods. NFS users: flock doesn't work, remember to change mmap_disable. #lock_method = fcntl -# Directory in which LDA/LMTP temporarily stores incoming mails >128 kB. +# Directory where mails can be temporarily stored. Usually it's used only for +# mails larger than >= 128 kB. It's used by various parts of Dovecot, for +# example LDA/LMTP while delivering large mails or zlib plugin for keeping +# uncompressed mails. #mail_temp_dir = /tmp # Valid UID range for users, defaults to 500 and above. This is mostly @@ -220,7 +223,7 @@ first_valid_uid = 1000 # Mailbox list indexes can be used to optimize IMAP STATUS commands. They are # also required for IMAP NOTIFY extension to be enabled. -#mailbox_list_index = no +#mailbox_list_index = yes # Trust mailbox list index to be up-to-date. This reduces disk I/O at the cost # of potentially returning out-of-date results after e.g. server crashes. @@ -364,7 +367,7 @@ mbox_write_locks = fcntl ## # Maximum dbox file size until it's rotated. -#mdbox_rotate_size = 2M +#mdbox_rotate_size = 10M # Maximum dbox file age until it's rotated. Typically in days. Day begins # from midnight, so 1d = today, 2d = yesterday, etc. 0 = check disabled. @@ -404,7 +407,8 @@ mbox_write_locks = fcntl # Settings to control adding $HasAttachment or $HasNoAttachment keywords. # By default, all MIME parts with Content-Disposition=attachment, or inlines # with filename parameter are consired attachments. -# add-flags-on-save - Add the keywords when saving new mails. +# add-flags - Add the keywords when saving new mails or when fetching can +# do it efficiently. # content-type=type or !type - Include/exclude content type. Excluding will # never consider the matched MIME part as attachment. Including will only # negate an exclusion (e.g. content-type=!foo/* content-type=foo/bar). diff --git a/dovecot/conf.d/10-metrics.conf b/dovecot/conf.d/10-metrics.conf new file mode 100644 index 0000000..f7a758f --- /dev/null +++ b/dovecot/conf.d/10-metrics.conf @@ -0,0 +1,74 @@ +## +## Statistics and metrics +## + +# Dovecot supports gathering statistics from events. +# Currently there are no statistics logged by default, and therefore they must +# be explicitly added using the metric configuration blocks. +# +# Unlike old stats, the new statistics do not require any plugins loaded. +# +# See https://doc.dovecot.org/configuration_manual/stats/ for more details. + +## +## Example metrics +## + +#metric auth_success { +# filter = event=auth_request_finished AND success=yes +#} +# +#metric auth_failures { +# filter = event=auth_request_finished AND NOT success=yes +#} +# +#metric imap_command { +# filter = event=imap_command_finished +# group_by = cmd_name tagged_reply_state +#} +# +#metric smtp_command { +# filter = event=smtp_server_command_finished +# group_by = cmd_name status_code duration:exponential:1:5:10 +#} +# +#metric mail_delivery { +# filter = event=mail_delivery_finished +# group_by = duration:exponential:1:5:10 +#} + +## +## Prometheus +## + +# To allow access to statistics with Prometheus, enable http listener +# on stats process. Stats will be available on /metrics path. +# +# See https://doc.dovecot.org/configuration_manual/stats/openmetrics/ for more +# details. + +#service stats { +# inet_listener http { +# port = 9900 +# } +#} + +## +## Event exporting +## + +# You can also export individual events. +# +# See https://doc.dovecot.org/configuration_manual/event_export/ for more +# details. + +#event_exporter log { +# format = json +# format_args = time-rfc3339 +# transport = log +#} +# +#metric imap_commands { +# exporter = log +# filter = event=imap_command_finished +#} diff --git a/dovecot/conf.d/10-ssl.conf.rpmnew b/dovecot/conf.d/10-ssl.conf.rpmnew new file mode 100644 index 0000000..0bee01e --- /dev/null +++ b/dovecot/conf.d/10-ssl.conf.rpmnew @@ -0,0 +1,85 @@ +## +## SSL settings +## + +# SSL/TLS support: yes, no, required. +# disable plain pop3 and imap, allowed are only pop3+TLS, pop3s, imap+TLS and imaps +# plain imap and pop3 are still allowed for local connections +ssl = required + +# PEM encoded X.509 SSL/TLS certificate and private key. They're opened before +# dropping root privileges, so keep the key file unreadable by anyone but +# root. Included doc/mkcert.sh can be used to easily generate self-signed +# certificate, just make sure to update the domains in dovecot-openssl.cnf +ssl_cert = ) instead of full path +# syntax. +# +# The list is space-separated. +#lmtp_client_workarounds = + protocol lmtp { # Space separated list of plugins to load (default is global mail_plugins). #mail_plugins = $mail_plugins diff --git a/dovecot/conf.d/auth-vpopmail.conf.ext b/dovecot/conf.d/auth-vpopmail.conf.ext deleted file mode 100644 index f2da976..0000000 --- a/dovecot/conf.d/auth-vpopmail.conf.ext +++ /dev/null @@ -1,17 +0,0 @@ -# Authentication for vpopmail users. Included from 10-auth.conf. -# -# - -passdb { - driver = vpopmail - - # [cache_key=] [webmail=] - args = -} - -userdb { - driver = vpopmail - - # [quota_template=