[strongSwan] strongSwan 5.1.2 on Ubuntu Trusty (14.0.4) and AppArmor

Martin Willi martin at strongswan.org
Thu Mar 19 14:32:17 CET 2015


Hi Fabrice,

> But when i execute "ipsec statusall" command, it replies :
> "reading from socket failed: Permission denied"
> 
> When i suppress "/etc/apparmor.d/usr.lib.ipsec.stroke" AppArmor
> profile, the command replies correctly.

We don't ship any AppArmor profiles from upstream, so you most likely
should report this issue to Ubuntu.

>   /run/charon.ctl               rw,

Not sure if/how this is symlinked and what paths have been configured in
Ubuntu, but usually that socket is opened over /var/run/charon.ctl.

Regards
Martin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 473 bytes
Desc: This is a digitally signed message part
URL: <http://lists.strongswan.org/pipermail/users/attachments/20150319/e84aaa93/attachment.pgp>


More information about the Users mailing list