* Tue Apr 18 2017 Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-225.13
- Add interface gssd_noatsecure()
- Add interface gssproxy_noatsecure()
- Fix policy to reflect all changes in new IPA release
- Allow tlp_t domain to ioctl removable devices BZ(1436830)
- Allow tlp_t domain domtrans into mount_t BZ(1442571)
- Allow lircd_t to read/write to sysfs BZ(1442443)
- Allow virtlogd_t to creating tmp files with virt_tmp_t labels.
- Allow sbd_t to read/write fixed disk devices
- Allow sendmail to search network sysctls
- Allow certmonger to start haproxy service
- Allow drbd load modules
- Revert "Add sys_module capability for drbd"
- Fix cockpit module
- Fix init Module
- Make groupadd_t domain as system bus client BZ(1416963)
- Allow init noatsecure for gssd and gssproxy
- Make useradd_t domain as system bus client BZ(1442572)
- Allow xdm_t to gettattr /dev/loop-control device BZ(1385090)
- Dontaudit gdm-session-worker to view key unknown. BZ(1433191)
- Allow staff user to read fwupd_cache_t files
- Allow xdm_t to execute files labeled as xdm_var_lib_t
- Remove /proc <<none>> from fedora policy, it's no longer necessary