summaryrefslogtreecommitdiffstats
path: root/doc/wiki/Plugins.Apparmor.txt
diff options
context:
space:
mode:
authorDaniel Baumann <daniel.baumann@progress-linux.org>2024-04-28 09:51:24 +0000
committerDaniel Baumann <daniel.baumann@progress-linux.org>2024-04-28 09:51:24 +0000
commitf7548d6d28c313cf80e6f3ef89aed16a19815df1 (patch)
treea3f6f2a3f247293bee59ecd28e8cd8ceb6ca064a /doc/wiki/Plugins.Apparmor.txt
parentInitial commit. (diff)
downloaddovecot-f7548d6d28c313cf80e6f3ef89aed16a19815df1.tar.xz
dovecot-f7548d6d28c313cf80e6f3ef89aed16a19815df1.zip
Adding upstream version 1:2.3.19.1+dfsg1.upstream/1%2.3.19.1+dfsg1upstream
Signed-off-by: Daniel Baumann <daniel.baumann@progress-linux.org>
Diffstat (limited to 'doc/wiki/Plugins.Apparmor.txt')
-rw-r--r--doc/wiki/Plugins.Apparmor.txt34
1 files changed, 34 insertions, 0 deletions
diff --git a/doc/wiki/Plugins.Apparmor.txt b/doc/wiki/Plugins.Apparmor.txt
new file mode 100644
index 0000000..d68f05d
--- /dev/null
+++ b/doc/wiki/Plugins.Apparmor.txt
@@ -0,0 +1,34 @@
+Apparmor plugin
+===============
+
+A simple plugin which allows changing "hat" (apparmor context) when user is
+loaded. Context is changed back to default on user deinit. Multiple hats are
+supported, and passed to apparmor_change_hatv function. Since v2.2.32.
+
+Configuration
+-------------
+
+---%<-------------------------------------------------------------------------
+mail_plugins = $mail_plugins apparmor
+
+plugin {
+ apparmor_hat = hat_name
+ apparmor_hat2 = another_hat
+}
+---%<-------------------------------------------------------------------------
+
+You can also specify hats from user or password database. If you provide from
+passdb, use userdb_apparmor_hat=hat and subsequent hats as userdb_apparmor_hat2
+and so forth. From userdb, you can omit the userdb_ prefix.
+
+It's also possible to combine these, so that you can provide some of the hats
+from config and some from passdb/userdb configuration. If you want to provide
+apparmor_hat2 from config, make sure you provide apparmor_hat from userdb or
+passdb always, otherwise apparmor_hat2 won't be seen.
+
+Debugging
+---------
+
+Set mail_debug=yes to see context changes.
+
+(This file was created from the wiki on 2019-06-19 12:42)