selinux-refpolicy/policy/modules/services/certbot.fc
Kenton Groombridge 3ce27e68d9
certbot: add support for acme.sh
Signed-off-by: Kenton Groombridge <me@concord.sh>
2021-02-01 15:29:24 -05:00

7 lines
446 B
Plaintext

/usr/bin/certbot -- gen_context(system_u:object_r:certbot_exec_t,s0)
/usr/bin/letsencrypt -- gen_context(system_u:object_r:certbot_exec_t,s0)
/usr/share/acme\.sh/acme\.sh -- gen_context(system_u:object_r:certbot_exec_t,s0)
/var/lib/letsencrypt(/.*)? gen_context(system_u:object_r:certbot_lib_t,s0)
/var/log/letsencrypt(/.*)? gen_context(system_u:object_r:certbot_log_t,s0)
/var/lib/acme\.sh(/.*)? gen_context(system_u:object_r:certbot_lib_t,s0)