summaryrefslogtreecommitdiffstats
path: root/pki/base/selinux
diff options
context:
space:
mode:
authorvakwetu <vakwetu@c9f7a03b-bd48-0410-a16d-cbbf54688b0b>2011-07-13 20:40:51 +0000
committervakwetu <vakwetu@c9f7a03b-bd48-0410-a16d-cbbf54688b0b>2011-07-13 20:40:51 +0000
commit6b523d3f3b48ba0ad1f32b746412719710fbd352 (patch)
tree7a1d99dee77799860c312caac35956fa0ad95b94 /pki/base/selinux
parent3ffa3490b4c1879b8539597c15c193628cbbe123 (diff)
downloadpki-6b523d3f3b48ba0ad1f32b746412719710fbd352.tar.gz
pki-6b523d3f3b48ba0ad1f32b746412719710fbd352.tar.xz
pki-6b523d3f3b48ba0ad1f32b746412719710fbd352.zip
Bugzilla #720503 - RA and TPS require additional SELinux permissions to run in Enforcing mode
git-svn-id: svn+ssh://svn.fedorahosted.org/svn/pki/trunk@2056 c9f7a03b-bd48-0410-a16d-cbbf54688b0b
Diffstat (limited to 'pki/base/selinux')
-rw-r--r--pki/base/selinux/src/pki.if5
-rw-r--r--pki/base/selinux/src/pki.te2
2 files changed, 6 insertions, 1 deletions
diff --git a/pki/base/selinux/src/pki.if b/pki/base/selinux/src/pki.if
index b94170b69..0917e03fb 100644
--- a/pki/base/selinux/src/pki.if
+++ b/pki/base/selinux/src/pki.if
@@ -612,6 +612,9 @@ template(`pki_tps_template',`
# allow writing to the kernel keyring
allow pki_tps_t self:key { write read };
+ # new for f14
+ apache_exec(pki_tps_t)
+
')
template(`pki_ra_template',`
@@ -793,6 +796,8 @@ template(`pki_ra_template',`
# allow writing to the kernel keyring
allow pki_ra_t self:key { write read };
+ # new for f14
+ apache_exec(pki_ra_t)
')
diff --git a/pki/base/selinux/src/pki.te b/pki/base/selinux/src/pki.te
index b0b91df91..9a4d376d1 100644
--- a/pki/base/selinux/src/pki.te
+++ b/pki/base/selinux/src/pki.te
@@ -1,4 +1,4 @@
-policy_module(pki,1.0.22)
+policy_module(pki,1.0.23)
attribute pki_ca_config;
attribute pki_ca_executable;