Skip to content
GitLab
  • Menu
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • S strongswan
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Merge requests 5
    • Merge requests 5
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages & Registries
    • Packages & Registries
    • Container Registry
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Jobs
  • Commits
Collapse sidebar
  • DebianDebian
  • strongswan
  • Merge requests
  • !12

apparmor: allow charon, charon-systemd and swanctl to read ssl keys from common locations

  • Review changes

  • Download
  • Email patches
  • Plain diff
Open Simon Deziel requested to merge sdeziel-guest/strongswan:apparmor-certbot into debian/master Oct 06, 2021
  • Overview 2
  • Commits 1
  • Pipelines 2
  • Changes 3

With the popularity of ACME clients providing access to free "official" TLS certs some users want to make use of those with strongSwan. The too restrictive AppArmor policy caused grief to some users which reported about it on the upstream mailing list:

https://lists.strongswan.org/pipermail/users/2017-February/010537.html https://lists.strongswan.org/pipermail/users/2021-October/015121.html

Signed-off-by: Simon Deziel simon@sdeziel.info

Assignee
Assign to
Reviewer
Request review from
Time tracking
Source branch: apparmor-certbot