add selinux-nginx rule to read cert_t (#75)

This commit is contained in:
Alexander Miroshnichenko 2020-05-20 15:52:04 +03:00 committed by GitHub
parent d1f782d920
commit ea69a0a9bf
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -22,6 +22,7 @@ optional_policy(`
')
allow nginx_t self:capability { dac_override dac_read_search };
miscfiles_read_generic_certs(nginx_t)
tunable_policy(`nginx_can_read_ebuild',`
portage_read_ebuild(nginx_t)