[Bug 2072702] Re: AppArmor profile prevents use of TLS keys and certificates

2024-07-11 Thread Andreas Hasenack
Note also the README.apparmor[1] explanation. Packages can also install
apparmor profile snippets in /etc/apparmor.d/rsyslog.d. If the default
of the freeipa package (or whatever produced /etc/ipa/ca.crt) is to
place certificate and keys in /etc/ipa, maybe it could ship such a
profile snippet.


1.
https://git.launchpad.net/ubuntu/+source/rsyslog/tree/debian/README.apparmor

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2072702

Title:
  AppArmor profile prevents use of TLS keys and certificates

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rsyslog/+bug/2072702/+subscriptions


-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 2072702] Re: AppArmor profile prevents use of TLS keys and certificates

2024-07-10 Thread Simon Déziel
@Orion, /etc/ipa isn't a standard location. I think you'd be better off
either adding a local override in
/etc/apparmor.d/local/usr.sbin.rsyslogd or maybe put the CA file
somewhere under /etc/rsyslog.d/. The later path is already something the
rsyslogd profile allows reading.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2072702

Title:
  AppArmor profile prevents use of TLS keys and certificates

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rsyslog/+bug/2072702/+subscriptions


-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs