We've been using the httpd_can_network_connect boolean for years to allow httpd to connect to the openQA server processes. This is an unnecessarily large hammer when we only need it to be able to connect to exactly the two openQA ports. This uses a custom SELinux policy to allow connecting to those ports only, and ensures the boolean is set back to off. Signed-off-by: Adam Williamson <awilliam@redhat.com>
1.1 KiB
1.1 KiB