apparmor doesn't allow access to kerberos keytab
Bug #189022 reported by
Jelmer Vernooij
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
cupsys (Ubuntu) |
Fix Released
|
Medium
|
Jelmer Vernooij |
Bug Description
affects /ubuntu/cupsys
The default apparmor configuration file for cupsd in
/etc/apparmor.
Kerberos keytabs.
The following patch fixes it for me:
--- usr.sbin.
+++ usr.sbin.cupsd 2007-10-29 16:27:20.000000000 +0100
@@ -102,8 +80,12 @@
# FIXME: no policy ATM for hplip
/usr/bin/hpijs Ux,
/usr/
/usr/
+
+ # Kerberos authentication
+ /etc/krb5.conf rw,
+ /etc/cups/
}
# separate profile since this needs to write into /home
--
Changed in cupsys: | |
status: | In Progress → Fix Committed |
Changed in cupsys (Ubuntu): | |
assignee: | nobody → Jelmer Vernooij (jelmer) |
To post a comment you must log in.
I added your patch to the AppArmor profile in the SVN repository for CUPS, so it will be added to the next cupsys package. Thank you for the patch, Jelmer.