selinux-policy/policy
Dominick Grift 8340621920 Implement miscfiles_cert_type().
This is based on Fedoras' miscfiles_cert_type implementation.
The idea was that openvpn needs to be able read home certificates (home_cert_t) which is not implemented in refpolicy yet, as well as generic cert_t certificates.

Note that openvpn is allowed to read all cert_types, as i know that it needs access to both generic cert_t as well as (future) home_cert_t. Dwalsh noted that other domains may need this as well but because i do not know exactly which domains i will not changes any other domains call to generic cert type interfaces.

Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-10 11:05:46 -04:00
..
flask Add module_request permission, from Dan Walsh. 2009-11-19 08:52:06 -05:00
modules Implement miscfiles_cert_type(). 2010-09-10 11:05:46 -04:00
support Create_lnk_perms fix from Russell Coker. 2010-06-28 09:33:17 -04:00
constraints Fix a typo of SElinux to SELinux. 2009-10-22 09:47:52 -04:00
global_booleans trunk: merge strict and targeted policies. merge shlib_t into lib_t. 2007-10-02 16:04:50 +00:00
global_tunables remove read_default_t tunable 2009-07-23 08:58:35 -04:00
mcs revise MCS constraints to use only MCS-specific attributes. 2009-10-07 11:48:14 -04:00
mls Add trusted object condition to unix socket connectto/sendto, to fix label translation. 2010-04-29 11:29:39 -04:00
policy_capabilities trunk: update policycaps comments for sock_file open perm. 2009-07-01 13:34:54 +00:00
rolemap trunk: merge UBAC. 2008-11-05 16:10:46 +00:00
users Typo in policy/users 2009-12-18 08:51:58 -05:00