freeipa/daemons/dnssec
Christian Heimes e881e35783 Fix various OpenDNSSEC 2.1 issues
Require OpenDNSSEC 2.1.6-5 with fix for RHBZ#1825812 (DAC override AVC)

Allow ipa-dnskeysyncd to connect to enforcer.sock (ipa_dnskey_t write
opendnssec_var_run_t and connectto opendnssec_t). The
opendnssec_stream_connect interface is available since 2016.

Change the owner of the ipa-ods-exporter socket to ODS_USER:ODS_GROUP.
The ipa-ods-exporter service already runs as ODS_USER.

Fixes: https://pagure.io/freeipa/issue/8283
Signed-off-by: Christian Heimes <cheimes@redhat.com>
Reviewed-By: Florence Blanc-Renaud <frenaud@redhat.com>
2020-04-21 21:37:06 +02:00
..
ipa-dnskeysync-replica.in Replace PYTHONSHEBANG with valid shebang 2019-06-24 09:35:57 +02:00
ipa-dnskeysyncd.in Replace PYTHONSHEBANG with valid shebang 2019-06-24 09:35:57 +02:00
ipa-dnskeysyncd.service.in configure: Use ODS_USER and NAMED_GROUP in daemons/dnssec/*.service.in 2017-03-22 13:39:18 +01:00
ipa-ods-exporter.in Support OpenDNSSEC 2.1: new ods-signer protocol 2020-03-12 21:48:25 +01:00
ipa-ods-exporter.service.in Fix various OpenDNSSEC 2.1 issues 2020-04-21 21:37:06 +02:00
ipa-ods-exporter.socket.in Fix various OpenDNSSEC 2.1 issues 2020-04-21 21:37:06 +02:00
Makefile.am Fix various OpenDNSSEC 2.1 issues 2020-04-21 21:37:06 +02:00