From Debian package 0.0.20080702-11 Mostly merged upstream in ada61e15 (2010-05-13) Grant setcap access to asterisk Let it use unix socket Index: policy/modules/services/asterisk.te =================================================================== --- policy/modules/services/asterisk.te.orig +++ policy/modules/services/asterisk.te @@ -45,7 +45,7 @@ allow asterisk_t self:fifo_file rw_fifo_file_perms; allow asterisk_t self:sem create_sem_perms; allow asterisk_t self:shm create_shm_perms; -allow asterisk_t self:unix_stream_socket connectto; +allow asterisk_t self:unix_stream_socket { connectto rw_stream_socket_perms }; allow asterisk_t self:tcp_socket create_stream_socket_perms; allow asterisk_t self:udp_socket create_socket_perms;