What is the best practice to manage selinux context for SSL sertificates. I usually prefer to use the same certificate/key for all applications: dovecot, sendmail, apache, cups to name a few. Do I have to have separate copies for each daemon or there is a common context exists for this purpoces?


Re: shared certificate

cert_t, I am not sure if all those domains can read cert_t, but if one can not it is a bug.

The /etc/pki directory has this label.

