Public bug reported:

af-alg is set to load=yes by default
No other component hit this yet, but swanctl complaind about

apparmor="DENIED" operation="create" profile="/usr/sbin/swanctl"
pid=4094 comm="swanctl" family="alg" sock_type="seqpacket" protocol=0
requested_mask="create" denied_mask="create"

lets add a rule for that to swanctl (since we didn#t see it anywhere
else not added to other strongswan profiles yet)

This rule will do it:
 network alg seqpacket,

** Affects: strongswan (Ubuntu)
     Importance: Undecided
         Status: Triaged

** Changed in: strongswan (Ubuntu)
       Status: New => Triaged

** Merge proposal linked:
   
https://code.launchpad.net/~paelzer/ubuntu/+source/strongswan/+git/strongswan/+merge/360447

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1807962

Title:
  please allow alg socket for af-alg

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/strongswan/+bug/1807962/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to