-
Bug
-
Resolution: Unresolved
-
Undefined
-
None
-
rhel-system-roles-1.99.1-0.1.el10
-
No
-
Low
-
rhel-system-roles
-
0
-
QE ack, Dev ack
-
False
-
False
-
-
Yes
-
Red Hat Enterprise Linux
-
None
-
Pass
-
Automated
-
Bug Fix
-
-
Done
-
Done
-
Done
-
Not Required
-
None
Cause: The timesync role is replacing the default `OPTIONS=` setting for chronyd with `""` upon every role run.
Consequence: This removes the default `OPTIONS="-F 2"` setting on EL9 and EL10 which weakens the security of chronyd.
Fix: Add `-F 2` as the default setting for `OPTIONS` in EL9 and EL10. Ensure that the user can override this setting if necessary, and ensure that this setting can co-exist with other `OPTIONS` settings that may be set by the user.
Result: The timesync role applies the correct security settings on every platform and allows the user to override/extend these settings.
Fixes #278
- links to
-
RHEA-2025:148879 rhel-system-roles bug fix and enhancement update