2011-03-25 09:04:51 +01:00
|
|
|
---
|
|
|
|
profiles/apparmor.d/abstractions/ldapclient | 21 +++++++++++++++++++++
|
|
|
|
profiles/apparmor.d/abstractions/nameservice | 8 +++-----
|
|
|
|
2 files changed, 24 insertions(+), 5 deletions(-)
|
|
|
|
|
2011-01-17 17:43:05 +01:00
|
|
|
--- /dev/null
|
2011-03-25 09:04:51 +01:00
|
|
|
+++ b/profiles/apparmor.d/abstractions/ldapclient
|
2011-01-17 17:43:05 +01:00
|
|
|
@@ -0,0 +1,21 @@
|
|
|
|
+# ------------------------------------------------------------------
|
|
|
|
+#
|
|
|
|
+# Copyright (C) 2011 Novell/SUSE
|
|
|
|
+#
|
|
|
|
+# This program is free software; you can redistribute it and/or
|
|
|
|
+# modify it under the terms of version 2 of the GNU General Public
|
|
|
|
+# License published by the Free Software Foundation.
|
|
|
|
+#
|
|
|
|
+# ------------------------------------------------------------------
|
|
|
|
+
|
|
|
|
+ # files required by LDAP clients (e.g. nss_ldap/pam_ldap)
|
|
|
|
+ /etc/ldap.conf r,
|
|
|
|
+ /etc/ldap.secret r,
|
|
|
|
+ /etc/openldap/* r,
|
|
|
|
+ /etc/openldap/cacerts/* r,
|
|
|
|
+
|
|
|
|
+ # SASL plugins and config
|
|
|
|
+ /etc/sasl2/* r,
|
|
|
|
+ /usr/lib{,32,64}/sasl2/* r,
|
|
|
|
+
|
|
|
|
+ #include <abstractions/ssl_certs>
|
2011-03-25 09:04:51 +01:00
|
|
|
--- a/profiles/apparmor.d/abstractions/nameservice
|
|
|
|
+++ b/profiles/apparmor.d/abstractions/nameservice
|
|
|
|
@@ -16,8 +16,6 @@
|
2011-01-17 17:43:05 +01:00
|
|
|
/etc/group r,
|
|
|
|
/etc/host.conf r,
|
|
|
|
/etc/hosts r,
|
|
|
|
- /etc/ldap.conf r,
|
|
|
|
- /etc/ldap.secret r,
|
|
|
|
/etc/nsswitch.conf r,
|
|
|
|
/etc/gai.conf r,
|
|
|
|
/etc/passwd r,
|
2011-03-25 09:04:51 +01:00
|
|
|
@@ -32,9 +30,6 @@
|
2011-01-17 17:43:05 +01:00
|
|
|
|
|
|
|
/etc/samba/lmhosts r,
|
|
|
|
/etc/services r,
|
|
|
|
- # all openldap config
|
|
|
|
- /etc/openldap/* r,
|
|
|
|
- /etc/ldap/** r,
|
|
|
|
# db backend
|
|
|
|
/var/lib/misc/*.db r,
|
|
|
|
# The Name Service Cache Daemon can cache lookups, sometimes leading
|
2011-03-25 09:04:51 +01:00
|
|
|
@@ -58,6 +53,9 @@
|
2011-01-17 17:43:05 +01:00
|
|
|
# nis
|
|
|
|
#include <abstractions/nis>
|
|
|
|
|
|
|
|
+ # ldap
|
|
|
|
+ #include <abstractions/ldapclient>
|
|
|
|
+
|
|
|
|
# winbind
|
|
|
|
#include <abstractions/winbind>
|
|
|
|
|