Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Allow ipa-otpd to access USB devices for passkeys
Main SELinux policy will allow transition of passkey_child (SSSD) to ipa_otpd_t context to perform FIDO2 operations with USB devices. This means ipa-otpd will need to be able to read data from sysfs and connect to USB devices. Add required permissions to IPA subpolicy as well. See rhbz#2238224 for discussion. Related: https://pagure.io/freeipa/issue/9434 Signed-off-by: Alexander Bokovoy <[email protected]> Reviewed-By: Zdenek Pytela <[email protected]> Reviewed-By: Florence Blanc-Renaud <[email protected]>
- Loading branch information