2010-04-20 17:08:57

by domg472

[permalink] [raw]
Subject: [refpolicy] [ certmonger patch 1/1] certmonger_t cannot restart apache service.

Introduced in 33793ec2ce002a8268ce2a2f835488a32adf2763

Signed-off-by: Dominick Grift <[email protected]>
---
:100644 100644 4881860... 3400228... M policy/modules/services/certmonger.if
policy/modules/services/certmonger.if | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)

diff --git a/policy/modules/services/certmonger.if b/policy/modules/services/certmonger.if
index 4881860..3400228 100644
--- a/policy/modules/services/certmonger.if
+++ b/policy/modules/services/certmonger.if
@@ -160,7 +160,7 @@ interface(`certmonger_admin',`
ps_process_pattern($1, certmonger_t)
allow $1 certmonger_t:process { ptrace signal_perms };

- # Allow certmonger_t to restart the apache service
+ # Allow certmonger_admin to restart the certmonger service
certmonger_initrc_domtrans($1)
domain_system_change_exemption($1)
role_transition $2 certmonger_initrc_exec_t system_r;
--
1.7.0.1

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20100420/a3ea2164/attachment.bin