New AppArmor profile: usr.sbin.nslcd
Bug #1575455 reported by
Daniel Richard G.
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
AppArmor |
New
|
Undecided
|
Unassigned | ||
apparmor (Ubuntu) |
New
|
Undecided
|
Unassigned |
Bug Description
nslcd is a good program to be covered by an AppArmor profile, as it communicates with an LDAP server and services queries from arbitrary local applications.
This new profile used the existing usr.sbin.nscd profile as a starting point.
tags: | added: aa-policy |
To post a comment you must log in.
That's a great start; I'm concerned about blocking the dgram protocols though -- will nslcd ever need to look up ldap server addresses via dns? Your site may not, but maybe someone else's will?
Thanks