[apparmor] [patch] Samba profile updates for ActiveDirectory / Kerberos

2017-08-22 Thread Christian Boltz
Hello, the Samba package used by the INVIS server (based on openSUSE) needs some additional Samba permissions for the added ActiveDirectory / Kerberos support. I propose this patch for 2.9, 2.10, 2.11 and trunk. [ samba.diff ] === modified file ./profiles/apparmor.d/abstractions/samba --- pro

Re: [apparmor] [patch] Samba profile updates for ActiveDirectory / Kerberos

2017-08-22 Thread Seth Arnold
On Tue, Aug 22, 2017 at 01:09:47PM +0200, Christian Boltz wrote: > Hello, > > the Samba package used by the INVIS server (based on openSUSE) needs > some additional Samba permissions for the added ActiveDirectory / > Kerberos support. Is the sss/ms/initgroups change intentional? Should that go in

Re: [apparmor] [patch] Samba profile updates for ActiveDirectory / Kerberos

2017-08-22 Thread Christian Boltz
Hello, Am Dienstag, 22. August 2017, 21:58:32 CEST schrieb Seth Arnold: > On Tue, Aug 22, 2017 at 01:09:47PM +0200, Christian Boltz wrote: > > the Samba package used by the INVIS server (based on openSUSE) needs > > some additional Samba permissions for the added ActiveDirectory / > > Kerberos sup

Re: [apparmor] [patch] Samba profile updates for ActiveDirectory / Kerberos

2017-08-28 Thread Seth Arnold
On Tue, Aug 22, 2017 at 11:14:59PM +0200, Christian Boltz wrote: > > Is the sss/ms/initgroups change intentional? > > Yes, this is intentional - I did the profile updates (on an INVIS server) > myself ;-) > > > Should that go into abstractions/nameservice instead? > > What about "maybe"? ;-)

Re: [apparmor] [patch] Samba profile updates for ActiveDirectory / Kerberos

2017-08-29 Thread Christian Boltz
Hello, Am Dienstag, 29. August 2017, 03:38:53 CEST schrieb Seth Arnold: > On Tue, Aug 22, 2017 at 11:14:59PM +0200, Christian Boltz wrote: > > > Is the sss/ms/initgroups change intentional? > > > > Yes, this is intentional - I did the profile updates (on an INVIS > > server) myself ;-) > > > > >