diff --git a/policy/modules/services/ssh.if b/policy/modules/services/ssh.if index cbd0cdd26..3fda88720 100644 --- a/policy/modules/services/ssh.if +++ b/policy/modules/services/ssh.if @@ -346,7 +346,7 @@ template(`ssh_role_template',` # SSH agent local policy # - allow $1_ssh_agent_t self:process setrlimit; + allow $1_ssh_agent_t self:process { setrlimit signal }; allow $1_ssh_agent_t self:capability setgid; allow $1_ssh_agent_t { $1_ssh_agent_t $3 }:process signull;