Apache should be confined with refpolicy 2:2.20131214-1 (and probably the previous one too), moreover "sesearch -A -s httpd_t -t shadow_t -c file" is returning nothing.
I'm closing this bug, feel free to reopen if you are still experiencing this bug. ** Changed in: refpolicy (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/203436 Title: selinux policy allows apache access to type shadow_t To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/refpolicy/+bug/203436/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs