Re: [Freeipa-devel] [PATCH] 414 Require new selinux-policy replacing old server-selinux subpackage

2013-07-17 Thread Martin Kosek
On 07/17/2013 04:04 PM, Alexander Bokovoy wrote: > On Wed, 17 Jul 2013, Martin Kosek wrote: >> Features of the new policy: >> - labels /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t which is >> writeable by PKI and readable by HTTPD >> - contains Conflicts with old freeipa-server-selinux package

Re: [Freeipa-devel] [PATCH] 414 Require new selinux-policy replacing old server-selinux subpackage

2013-07-17 Thread Alexander Bokovoy
On Wed, 17 Jul 2013, Martin Kosek wrote: Features of the new policy: - labels /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t which is writeable by PKI and readable by HTTPD - contains Conflicts with old freeipa-server-selinux package to avoid SELinux upgrade issues https://fedorahosted.org/f

[Freeipa-devel] [PATCH] 414 Require new selinux-policy replacing old server-selinux subpackage

2013-07-17 Thread Martin Kosek
Features of the new policy: - labels /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t which is writeable by PKI and readable by HTTPD - contains Conflicts with old freeipa-server-selinux package to avoid SELinux upgrade issues https://fedorahosted.org/freeipa/ticket/3788 SELinux policy