I started a completely new instance of Tumbleweed with copies of configuration files of my older instance. In this version I have DENIED lines in /var/log/audit/audit.log like the following: type=AVC msg=audit(1511788972.455:92): apparmor="DENIED" operation="signal" profile="/usr/sbin/dovecot" pid=1750 comm="dovecot" requested_mask="send" denied_mask="send" signal=rtmin+772495128 peer="/usr/lib/dovecot/ssl-params" type=AVC msg=audit(1511788972.763:93): apparmor="DENIED" operation="signal" profile="/usr/sbin/dovecot" pid=1750 comm="dovecot" requested_mask="send" denied_mask="send" signal=rtmin+745525016 peer="/usr/lib/dovecot/auth" type=AVC msg=audit(1511793889.785:175): apparmor="DENIED" operation="signal" profile="/usr/sbin/dovecot" pid=1750 comm="dovecot" requested_mask="send" denied_mask="send" signal=rtmin+772495128 peer="/usr/lib/dovecot/ssl-params" type=AVC msg=audit(1511793890.617:176): apparmor="DENIED" operation="signal" profile="/usr/sbin/dovecot" pid=1750 comm="dovecot" requested_mask="send" denied_mask="send" signal=rtmin+745525016 peer="/usr/lib/dovecot/auth" type=AVC msg=audit(1511799100.748:51): apparmor="DENIED" operation="capable" profile="/usr/sbin/dovecot" pid=1713 comm="dovecot" capability=2 capname="dac_read_search" type=AVC msg=audit(1511812782.369:123): apparmor="DENIED" operation="capable" profile="/usr/sbin/dovecot" pid=11831 comm="dovecot" capability=2 capname="dac_read_search" type=AVC msg=audit(1511812930.757:129): apparmor="DENIED" operation="capable" profile="/usr/sbin/dovecot" pid=11925 comm="dovecot" capability=2 capname="dac_read_search" I did create the file /etc/apparmor.d/local/usr.lib.dovecot.auth like below: # more /etc/apparmor.d/local/usr.lib.dovecot.auth # Site-specific additions and overrides for 'usr.lib.dovecot.auth' capability dac_read_search, capability dac_override,