c36abb7d55
- install SubDomain.pm compat module (bnc#713408) - Update to 2.6.1. - One patch eliminated - Lots of minor fixes - Split out more common abstractions - Add check_for_apparmor() helper. - dhcpd: Fix apparmor profile (bnc#692428) - Fixed typos in descriptions and summaries of apparmor.spec - move the requires and prerequires to the right package OBS-URL: https://build.opensuse.org/request/show/81356 OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=20
61 lines
1.7 KiB
Plaintext
61 lines
1.7 KiB
Plaintext
---
|
|
profiles/apparmor.d/abstractions/ldapclient | 21 +++++++++++++++++++++
|
|
profiles/apparmor.d/abstractions/nameservice | 8 +++-----
|
|
2 files changed, 24 insertions(+), 5 deletions(-)
|
|
|
|
--- /dev/null
|
|
+++ b/profiles/apparmor.d/abstractions/ldapclient
|
|
@@ -0,0 +1,21 @@
|
|
+# ------------------------------------------------------------------
|
|
+#
|
|
+# Copyright (C) 2011 Novell/SUSE
|
|
+#
|
|
+# This program is free software; you can redistribute it and/or
|
|
+# modify it under the terms of version 2 of the GNU General Public
|
|
+# License published by the Free Software Foundation.
|
|
+#
|
|
+# ------------------------------------------------------------------
|
|
+
|
|
+ # files required by LDAP clients (e.g. nss_ldap/pam_ldap)
|
|
+ /etc/ldap.conf r,
|
|
+ /etc/ldap.secret r,
|
|
+ /etc/openldap/* r,
|
|
+ /etc/openldap/cacerts/* r,
|
|
+
|
|
+ # SASL plugins and config
|
|
+ /etc/sasl2/* r,
|
|
+ /usr/lib{,32,64}/sasl2/* r,
|
|
+
|
|
+ #include <abstractions/ssl_certs>
|
|
--- a/profiles/apparmor.d/abstractions/nameservice
|
|
+++ b/profiles/apparmor.d/abstractions/nameservice
|
|
@@ -16,8 +16,6 @@
|
|
/etc/group r,
|
|
/etc/host.conf r,
|
|
/etc/hosts r,
|
|
- /etc/ldap.conf r,
|
|
- /etc/ldap.secret r,
|
|
/etc/nsswitch.conf r,
|
|
/etc/gai.conf r,
|
|
/etc/passwd r,
|
|
@@ -32,9 +30,6 @@
|
|
|
|
/etc/samba/lmhosts r,
|
|
/etc/services r,
|
|
- # all openldap config
|
|
- /etc/openldap/* r,
|
|
- /etc/ldap/** r,
|
|
# db backend
|
|
/var/lib/misc/*.db r,
|
|
# The Name Service Cache Daemon can cache lookups, sometimes leading
|
|
@@ -60,6 +55,9 @@
|
|
# nis
|
|
#include <abstractions/nis>
|
|
|
|
+ # ldap
|
|
+ #include <abstractions/ldapclient>
|
|
+
|
|
# winbind
|
|
#include <abstractions/winbind>
|
|
|