Does any one know how to modify the bind apparmor profile to allow reading from name="/usr/local/lib/libGeoIP.so.1.4.6". The apparmor is the default one that ships with Ubuntu 10.04 by default.
I'm thinking something like...
/usr/local/lib/** r
Or
/usr/local/lib/ r
Which one is correct.
Error message.
I included my named apparmor profile as attachment.Code:Dec 2 08:55:58 universal-mechanism kernel: [114310.720001] type=1503 audit(1291305358.425:23): operation="open" pid=10765 parent=10758 profile="/usr/sbin/named" requested_mask="r::" denied_mask="r::" fsuid=0 ouid=0 name="/usr/local/lib/libGeoIP.so.1.4.6"



Adv Reply

Bookmarks