[Pkg-giraffe-maintainers] Bug#934459: AppArmor configuration doesn't cover openssl.cnf in /etc/ssl/
Martin Wolf
mwolf at adiumentum.com
Sun Aug 11 11:09:03 BST 2019
Package: kopano-dagent
Version: 8.7.0-3
The default AppArmor configuration file
/etc/apparmor.d/usr.sbin.kopano-dagent doesn't cover /etc/ssl/openssl.cnf
Adding "/etc/ssl/openssl.cnf r," to
/etc/apparmor.d/usr.sbin.kopano-dagent seems to help.
Error without the modified AppArmor policy:
Aug 11 11:48:44 admailserver kernel: [24016.756487] audit: type=1400
audit(1565516924.187:212): apparmor="DENIED" operation="open"
profile="/usr/sbin/kopano-dagent" name="/etc/ssl/openssl.cnf" pid=31959
comm="kopano-dagent" requested_mask="r" denied_mask="r" fsuid=110 ouid=0
Linux 4.19.0-5-amd64 #1 SMP Debian 4.19.37-5+deb10u2 (2019-08-08) x86_64
GNU/Linux
More information about the Pkg-giraffe-maintainers
mailing list