883107e - Allow domains to use kerberos to read file_context file

Authored and Committed by mgrepl 11 years ago
    - Allow domains to use kerberos to read file_context file
    - Allow mozilla_plugin to connect to port 8081
    - Tighten security on virtual machines
    - block_suspend is caps2
    - Allow realmd to run ipa, really needs to be an unconfined_domain
    - Allow sandbox domains to use inherted terminals
    - Allow pscd to use devices labeled svirt_image_t in order to use cat cards.
    - Add label for new alsa pid
    - Alsa now uses a pid file and needs to setsched
    - Allow nova domains to connect to mysql port
    - Allow quantum to connect to keystone port
    - Allow nova-console to talk with mysql over unix stream socket
    - Allow dirsrv to stream connect to uuidd
    - Fix transition for cobbler lib files
    - Label all nagios plugin as unconfined by default
    - Add httpd_serve_cobbler_files()
    - Allow mdadm to read /dev/sr0 and create tmp files
    - Allow certwatch to send mails
    - Allow livecd to transition to rpm_script_t
    - Add cache dir support for cobbler
    - label shared libraries in /opt/google/chrome as testrel_shlib_t
    - Fix labeling for nagios plugins
    - Disable support for .xsession-errors-:[digit] file name transition for now unti
    
        
file modified
+115 -73
file modified
+328 -171
file modified
+26 -1