Merge pull request #418 from thinred/pr-apparmor

added apparmor profile
This commit is contained in:
Tatsuhiro Tsujikawa 2015-11-07 22:59:43 +09:00
commit aecddc2cda
1 changed files with 16 additions and 0 deletions

16
contrib/usr.sbin.nghttpx Normal file
View File

@ -0,0 +1,16 @@
#include <tunables/global>
/usr/sbin/nghttpx {
#include <abstractions/base>
#include <abstractions/nameservice>
#include <abstractions/openssl>
capability setgid,
capability setuid,
/usr/sbin/nghttpx rmix, # allow to run itself
/etc/nghttpx/nghttpx.conf r, # allow to read the config file
/etc/ssl/** r, # give access to ssl keys
/{,var/}run/nghttpx.pid lw, # allow to store a pid file
}