2020-12-29 17:21:36 +01:00
|
|
|
abi <abi/3.0>,
|
|
|
|
|
2020-04-20 17:32:53 +02:00
|
|
|
#include <tunables/global>
|
|
|
|
|
2020-12-29 17:21:36 +01:00
|
|
|
profile coturn /usr/{bin,sbin}/turnserver flags=(attach_disconnected) {
|
2020-04-20 17:32:53 +02:00
|
|
|
#include <abstractions/base>
|
|
|
|
#include <abstractions/nameservice>
|
|
|
|
#include <abstractions/user-tmp>
|
|
|
|
|
|
|
|
/etc/coturn/*.conf r,
|
2023-10-14 16:37:36 +02:00
|
|
|
/etc/coturn/tls/* r,
|
|
|
|
/etc/letsencrypt/archive/** r,
|
|
|
|
|
2020-04-20 17:32:53 +02:00
|
|
|
/usr/bin/turnserver mr,
|
|
|
|
owner /run/coturn/* w,
|
2020-12-29 17:21:36 +01:00
|
|
|
owner /var/lib/coturn r,
|
2020-04-20 17:32:53 +02:00
|
|
|
owner /var/lib/coturn/* rwk,
|
|
|
|
owner /var/log/coturn/*.log rw,
|
|
|
|
owner /var/log/turn*.log w,
|
|
|
|
|
2020-12-29 17:21:36 +01:00
|
|
|
deny /etc/ssl/openssl.cnf r,
|
|
|
|
|
2020-04-20 17:32:53 +02:00
|
|
|
# Site-specific additions and overrides. See local/README for details.
|
|
|
|
#include <local/usr.bin.turnserver>
|
|
|
|
}
|