https://bugzilla.novell.com/show_bug.cgi?id=857122
https://bugzilla.novell.com/show_bug.cgi?id=857122#c3
--- Comment #3 from Christian Boltz
The "/proc/sys/crypto/fips_enabled r," should IMHO be integrated in the upstream abstractions/openssl as this is not critical if you run without FIPS, but it will produce a lot of log entries on systems like SLES that are FIPS aware.
I just proposed this upstream.
In the meantime, you can already simplify your apparmor-abstractions-ssl:
#include
I need to find a way (via "%if 0%{?suse_version}" in the spec file) to provide the correct files for all current (open)SUSE distributions...
It shouldn't hurt to allow a bit more than really needed ;-) - especially if you already (have to) allow it for newer versions. Besides that: yes, I'd also love to have a %elseif. The workaround is to use nested %if / %else - it won't look too nice, but it works ;-) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.