aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKenton Groombridge <concord@gentoo.org>2024-05-06 15:59:55 -0400
committerKenton Groombridge <concord@gentoo.org>2024-05-14 13:41:35 -0400
commit304a909724d2e15445449257a45563751eb88a7c (patch)
tree777463c7d4d5dc1d70d517c0e29fe83e6fbf4862
parentfail2ban: allow reading net sysctls (diff)
downloadhardened-refpolicy-304a909724d2e15445449257a45563751eb88a7c.tar.gz
hardened-refpolicy-304a909724d2e15445449257a45563751eb88a7c.tar.bz2
hardened-refpolicy-304a909724d2e15445449257a45563751eb88a7c.zip
dovecot: allow dovecot-auth to read SASL keytab
Signed-off-by: Kenton Groombridge <concord@gentoo.org>
-rw-r--r--policy/modules/services/dovecot.te4
1 files changed, 4 insertions, 0 deletions
diff --git a/policy/modules/services/dovecot.te b/policy/modules/services/dovecot.te
index 11ffbb17..93721983 100644
--- a/policy/modules/services/dovecot.te
+++ b/policy/modules/services/dovecot.te
@@ -322,6 +322,10 @@ optional_policy(`
')
optional_policy(`
+ sasl_read_keytab(dovecot_auth_t)
+')
+
+optional_policy(`
postgresql_unpriv_client(dovecot_auth_t)
tunable_policy(`dovecot_can_connect_db',`