After some more discussion, what will be allowed is:
/etc/dhcp/ddns-keys/** r,
That directory will be created at install time, owned by root:dhcpd and mode 750. The apparmor rule comment and the changelog will both encourage people to generate separate keys and copy them into that directory.
After some more discussion, what will be allowed is: ddns-keys/ ** r,
/etc/dhcp/
That directory will be created at install time, owned by root:dhcpd and mode 750. The apparmor rule comment and the changelog will both encourage people to generate separate keys and copy them into that directory.