From be327e21ce1877b944508b4ff14101dc3c922d0c Mon Sep 17 00:00:00 2001 From: Martin Kosek Date: Jul 17 2013 14:20:02 +0000 Subject: Require new selinux-policy replacing old server-selinux subpackage Features of the new policy: - labels /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t which is writeable by PKI and readable by HTTPD - contains Conflicts with old freeipa-server-selinux package to avoid SELinux upgrade issues https://fedorahosted.org/freeipa/ticket/3788 --- diff --git a/freeipa.spec.in b/freeipa.spec.in index f0f1fc6..b455259 100644 --- a/freeipa.spec.in +++ b/freeipa.spec.in @@ -129,7 +129,7 @@ Requires: python-memcached Requires: systemd-units >= 38 Requires(pre): systemd-units Requires(post): systemd-units -Requires: selinux-policy >= 3.11.1-86 +Requires: selinux-policy >= 3.12.1-65 Requires(post): selinux-policy-base Requires: slapi-nis >= 0.44 Requires: pki-ca >= 10.0.2 @@ -776,6 +776,10 @@ fi %ghost %attr(0644,root,apache) %config(noreplace) %{_sysconfdir}/ipa/ca.crt %changelog +* Wed Jul 17 2013 Martin Kosek - 3.2.1-4 +- Require selinux-policy 3.12.1-65 containing missing policy after removal of + freeipa-server-selinux subpackage + * Tue Jul 16 2013 Martin Kosek - 3.2.1-3 - Drop freeipa-server-selinux subpackage - Drop redundant directory /var/cache/ipa/sessions