Comment 1 for bug 1970455

Revision history for this message
Sergio Durigan Junior (sergiodj) wrote :

Thanks for taking the time to report this bug, Sebastian.

I'm adding it to the Ubuntu Server queue; as you mentioned, this is a relatively old issue and IIUC there's been some pushback to implement this. As Christian mentioned in the Debian bug, enabling write access via the apparmor profile by default could be interpreted as a security risk, so we have to take a deeper look into this problem before we proceed.

FWIW, I haven't tried to reproduce this bug locally, but I am setting its status as Triaged because it's pretty clear that the apparmor profile still doesn't allow strongswan to write to /etc/resolv.conf.