From 1dcbb3adfae78e6f46ff76f72d651d75850c46ab Mon Sep 17 00:00:00 2001 From: Martin Kosek Date: Wed, 17 Jul 2013 16:21:14 +0200 Subject: Require new selinux-policy replacing old server-selinux subpackage Features of the new policy: - labels /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t which is writeable by PKI and readable by HTTPD - contains Conflicts with old freeipa-server-selinux package to avoid SELinux upgrade issues https://fedorahosted.org/freeipa/ticket/3788 --- freeipa.spec.in | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/freeipa.spec.in b/freeipa.spec.in index 2f241b22c..93c69e591 100644 --- a/freeipa.spec.in +++ b/freeipa.spec.in @@ -130,7 +130,7 @@ Requires: python-memcached Requires: systemd-units >= 38 Requires(pre): systemd-units Requires(post): systemd-units -Requires: selinux-policy >= 3.11.1-86 +Requires: selinux-policy >= 3.12.1-65 Requires(post): selinux-policy-base Requires: slapi-nis >= 0.44 Requires: pki-ca >= 10.0.2 @@ -825,6 +825,10 @@ fi %endif # ! %{ONLY_CLIENT} %changelog +* Wed Jul 17 2013 Martin Kosek - 3.2.99-7 +- Require selinux-policy 3.12.1-65 containing missing policy after removal of + freeipa-server-selinux subpackage + * Tue Jul 16 2013 Tomas Babej - 3.2.99-6 - Do not create /var/lib/ipa/pki-ca/publish, retain reference as ghost -- cgit