>>>>> "JLT" == Jason L Tibbitts, <Jason> writes: JLT> Partially. The nscd control socket stuff (-g, -K, -i) works JLT> fine, but it still gets traps access to JLT> /usr/share/ssl/certs/cacert.pem: That should be /usr/share/ssl/cacert.pem. I note that the new policy changes the context on /usr/share/ssl/certs; perhaps I should just move cacert.pem there? Or would /etc/certs be better? I only chose the current location because I saw an example that put it there. - J<