profile.d/{01gnupg,01seccure}: Distinct secrecy/integrity sections.
authorMark Wooding <mdw@distorted.org.uk>
Sun, 12 Feb 2012 23:07:24 +0000 (23:07 +0000)
committerMark Wooding <mdw@distorted.org.uk>
Mon, 13 Feb 2012 00:25:30 +0000 (00:25 +0000)
So that they actually include the correct ACLs.

profile.d/01gnupg
profile.d/01seccure

index 182769c..1f897b5 100644 (file)
@@ -100,8 +100,11 @@ realname = %{realname}
 comment = %{comment-nil}
 email = %{email}
 
-[gnupg]
-@include = %gnupg %asymmetric
+[gnupg-integrity]
+@include = %gnupg %asymmetric-integrity
+
+[gnupg-secrecy]
+@include = %gnupg %asymmetric-secrecy
 
 [%gnupg-infra]
 @include = %gnupg
index 79d9e2a..3e77762 100644 (file)
@@ -48,8 +48,11 @@ curve = p256
 ;; MAC tag length.
 tagsz = 128
 
-[seccure]
-@include = %seccure %asymmetric
+[seccure-integrity]
+@include = %seccure %asymmetric-integrity
+
+[seccure-secrecy]
+@include = %seccure %asymmetric-secrecy
 
 [%seccure-infra]
 @include = %seccure