On Tue, 2015-03-10 at 14:43 +0100, Andrea Dell'Amico wrote:
#============= logrotate_t ============== allow logrotate_t fail2ban_client_exec_t:file { ioctl read execute execute_no_trans open };
Looks like this was already fixed in 'selinux-policy'. See https://bugzilla.redhat.com/show_bug.cgi?id=1114821
John.