* Tue Oct 24 2017 Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-260.14
- Allow l2tpd_t domain to send SIGKILL to ipsec_mgmt_t domains BZ(1505220)
- Allow dnssec_trigger_t domain to execute binaries with dnssec_trigeer_exec_t BZ(1487912)
- Allow thumb_t creating thumb_home_t files in user_home_dir_t direcotry BZ(1474110)
- Allow httpd_t also read httpd_user_content_type dirs when httpd_enable_homedirs is enables
- Allow svnserve to use kerberos
- Allow conman to use ptmx. Add conman_use_nfs boolean
- Allow svnserve to manage own svnserve_log_t files/dirs
- Label also compressed logs in /var/log for different services
- Allow haproxy daemon to reexec itself. BZ(1447800)
- Allow conmand to use usb ttys.
- Fix typo in ipa_cert_filetrans_named_content() interface
- Fix typo bug in summary of xguest SELinux module
- Allow postfix_master_t to bind to unreserved TCP ports. BZ(1373939)
- Allow rhsmcertd_t to send null signall for check snmpd_t process existence
- Allow rngd_t domain to use usb ttys
- Allow tlp domain to read sssd public files Allow tlp domain to mmap kernel modules
- Allow fsdaemon to use nsswitch BZ(1499498)
- Label postgresql-check-db-dir as postgresql_exec_t
- Allow systemd to read sysfs sym links. BZ(1499327)