~usmteam/usm/usm_directory

« back to all changes in this revision

Viewing changes to usr.sbin.slapd

  • Committer: oly at digitaloctave
  • Date: 2010-11-28 21:41:43 UTC
  • Revision ID: oly@digitaloctave.com-20101128214143-9cw5kqplc0xqmd13
rearrangedĀ files

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
# vim:syntax=apparmor
 
2
# Last Modified: Fri Jan  4 15:18:13 2008
 
3
# Author: Jamie Strandboge <jamie@ubuntu.com>
 
4
 
 
5
#include <tunables/global>
 
6
 
 
7
/usr/sbin/slapd {
 
8
  #include <abstractions/base>
 
9
  #include <abstractions/nameservice>
 
10
 
 
11
  #include <abstractions/ssl_certs>
 
12
  /etc/ssl/private/ r,
 
13
  /etc/ssl/private/* r,
 
14
 
 
15
  /etc/sasldb2 r,
 
16
 
 
17
  capability dac_override,
 
18
  capability net_bind_service,
 
19
  capability setgid,
 
20
  capability setuid,
 
21
 
 
22
  /etc/gai.conf r,
 
23
  /etc/hosts.allow r,
 
24
  /etc/hosts.deny r,
 
25
 
 
26
  # ldap files
 
27
  /etc/ldap/** kr,
 
28
  /etc/ldap/slapd.d/** rw,
 
29
 
 
30
  # kerberos/gssapi
 
31
  /dev/tty rw,
 
32
  /etc/krb5.keytab kr,
 
33
  /var/tmp/ rw,
 
34
  /var/tmp/** rw,
 
35
 
 
36
  # the databases and logs
 
37
  /var/lib/ldap/ r,
 
38
  #folders and files under this path
 
39
  /var/lib/ldap/** rw, 
 
40
  # lock file
 
41
  /var/lib/ldap/alock kw,
 
42
 
 
43
  # pid files and sockets
 
44
  /var/run/slapd/* w,
 
45
 
 
46
  /usr/lib/ldap/ r,
 
47
  /usr/lib/ldap/* mr,
 
48
 
 
49
  /usr/sbin/slapd mr,
 
50
}