Helmut Pozimski
|
066007f4ef
atop: allow management of log files
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
c0f0bf03d9
postfix: update policy and merge with local changes
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
add769bacb
amavis: allow management of links of type amavis_var_lib_t
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
eb9c7bdd35
acmetool: allow kernel_read_vm_overcommit_sysctl
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
b9923df92b
Merge branch 'acmetool_updater' of Hoshpak/selinux-policies into master
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
12ec32fceb
acme-updater: fix type transition for ejabberd
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
0147203c60
acme-updater: make external dependencies optional
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
0d1c510e34
acme-updater: add json configuration file and file context
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
359d65589f
update bind policy to cover unbound on Debian 8.x
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
5f8b500cf4
specify role for jabber admin in acme-updater policy
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
7ab04446b5
aloow acmeupdater to manager ejabberd and write to files in etc, needed for the ejabberd certificates
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
52999703a0
acme-updater: allow execution of apache binaries (e.g. apachectl)
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
7a5106ea2d
acme-updater: fix script name
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
bd28010154
change files for acme-updater to adapt to the new version
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
9f4c1054cf
allow acme_updater to read generic lock files (fixes #6)
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
b9873111be
allow acme_updater to give itself the capability sys_resource (fixes #7)
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
48bf495bb1
allow acme_updater to manage cert_t files to enable creating backups of dovecot cert files (fixes #5)
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
e8ad21f6f0
allow drac_overrid to acme-updater so it can read the bind session key
|
%!s(int64=8) %!d(string=hai) anos |
Helmut Pozimski
|
6455a55069
allow acme-updater to read binds run files
|
%!s(int64=8) %!d(string=hai) anos |
Helmut Pozimski
|
87b53501e3
allow acme-updater to resolve dns records
|
%!s(int64=8) %!d(string=hai) anos |
Helmut Pozimski
|
ae76aa8400
allow acme-updater to manage dovecot and postfix
|
%!s(int64=8) %!d(string=hai) anos |
Helmut Pozimski
|
0b7aeae0f7
allow apache to read phpfpm temp files to work around wrong contexts created by php file upload
|
%!s(int64=8) %!d(string=hai) anos |
Helmut Pozimski
|
f0936b3db5
allow acme-updater to search var_lib_t
|
%!s(int64=8) %!d(string=hai) anos |
Helmut Pozimski
|
0a8038d9e8
add missing permissions to acme-updater
|
%!s(int64=8) %!d(string=hai) anos |
Helmut Pozimski
|
16f3a4fecf
add policy for acme-updater
|
%!s(int64=8) %!d(string=hai) anos |
Helmut Pozimski
|
1632ea18a5
logrotate: update to the version from stretch and merge with my own changes
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
12a3653f9f
atop: update policy with missing permissions
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
c5f59a0683
jabber: allow kernel_read_vm_overcommit_sysctl and extend policy to use a cache directory for httpupload
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
ee1bc1d3bd
atop: extend policy to also cover atopacct
|
%!s(int64=7) %!d(string=hai) anos |
Helmut Pozimski
|
26636d0339
murmur: correct path to run directory
|
%!s(int64=7) %!d(string=hai) anos |