And back to apparmor.. The profile does need some changes, but no
modifications to openssh AIUI. Here's what I had to add:
/etc/default/locale r,
/var/cache/nscd/group r,
/var/cache/nscd/passwd r,
/etc/selinux/config r,
/etc/selinux/default/seusers r,
/etc/krb5.conf r,
/etc/krb5.keyt
moving to openssh, since the patch is needed there?
(I'm currently evaluating apparmor, so would like to confine sshd)
** Changed in: openssh (Ubuntu)
Sourcepackagename: apparmor => openssh
--
sshd profile does not work out-of-the-box
https://bugs.launchpad.net/bugs/228229
You received this bug