summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorSven Vermeulen <sven.vermeulen@siphos.be>2014-11-22 22:16:41 +0100
committerJason Zaman <jason@perfinion.com>2014-12-03 01:06:11 +0400
commit1ccd1cfc6d66c662c006169d458ab9c305490151 (patch)
treefdfa5a65cd32e2b9ad4b255d8e5c3078b0ecefb3
parentAdd gfisk and efibootmgr as fsadm_exec_t (diff)
downloadhardened-refpolicy-1ccd1cfc6d66c662c006169d458ab9c305490151.tar.gz
hardened-refpolicy-1ccd1cfc6d66c662c006169d458ab9c305490151.tar.bz2
hardened-refpolicy-1ccd1cfc6d66c662c006169d458ab9c305490151.zip
Add /var/lib/racoon as runtime directory for ipsec
-rw-r--r--policy/modules/system/ipsec.fc2
1 files changed, 2 insertions, 0 deletions
diff --git a/policy/modules/system/ipsec.fc b/policy/modules/system/ipsec.fc
index 082ce4751..47f932745 100644
--- a/policy/modules/system/ipsec.fc
+++ b/policy/modules/system/ipsec.fc
@@ -31,6 +31,8 @@
/usr/sbin/racoon -- gen_context(system_u:object_r:racoon_exec_t,s0)
/usr/sbin/setkey -- gen_context(system_u:object_r:setkey_exec_t,s0)
+/var/lib/racoon(/.*)? gen_context(system_u:object_r:ipsec_var_run_t,s0)
+
/var/lock/subsys/ipsec -- gen_context(system_u:object_r:ipsec_mgmt_lock_t,s0)
/var/log/pluto\.log -- gen_context(system_u:object_r:ipsec_log_t,s0)