meta-security: subtree update:95fe86eb98..7831969f8c

Alexander Kanavin (1):
      apparmor: pull in coreutils/findutils only when not using systemd as init manager

Armin Kuster (7):
      tpm2-tools: update to 4.1.3
      tpm2-tss: update to 2.4.1
      tpm2-tss-engine: add branch to SRC_URI & update to tip
      tpm2-pkcs11: update 1.2.0
      libtpm: update to 0.7.2
      openscap: update to 1.3.3
      tpm2-tcti-uefi: drop patch no longer needed

Jeremy Puhlman (2):
      clamav: resolve multilib issues
      tripwire: Remove makefiles from the man directories.

Kai Kang (1):
      sssd: disable build secrets

Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
Change-Id: I1e19d2563541504bcf89f1f70c680bd7e7e62d6c
diff --git a/meta-security/recipes-security/sssd/sssd_1.16.4.bb b/meta-security/recipes-security/sssd/sssd_1.16.4.bb
index 7ea1586..2c3c803 100644
--- a/meta-security/recipes-security/sssd/sssd_1.16.4.bb
+++ b/meta-security/recipes-security/sssd/sssd_1.16.4.bb
@@ -39,8 +39,7 @@
 
 PACKAGECONFIG[autofs] = "--with-autofs, --with-autofs=no"
 PACKAGECONFIG[crypto] = "--with-crypto=libcrypto, , libcrypto"
-PACKAGECONFIG[curl] = "--with-secrets --with-kcm, --without-secrets --without-kcm, curl jansson"
-PACKAGECONFIG[http] = "--with-secrets, --without-secrets, apache2"
+PACKAGECONFIG[curl] = "--with-kcm, --without-kcm, curl jansson"
 PACKAGECONFIG[infopipe] = "--with-infopipe, --with-infopipe=no, "
 PACKAGECONFIG[manpages] = "--with-manpages, --with-manpages=no"
 PACKAGECONFIG[nl] = "--with-libnl, --with-libnl=no, libnl"
@@ -60,6 +59,7 @@
     --without-python2-bindings \
     --enable-pammoddir=${base_libdir}/security \
     --without-python2-bindings \
+    --without-secrets \
 "
 
 do_configure_prepend() {
@@ -85,6 +85,7 @@
     # Remove /var/run as it is created on startup
     rm -rf ${D}${localstatedir}/run
 
+    rm -f ${D}${systemd_system_unitdir}/sssd-secrets.*
 }
 
 pkg_postinst_ontarget_${PN} () {
@@ -109,8 +110,6 @@
     sssd-pam-priv.socket \
     sssd-pam.service \
     sssd-pam.socket \
-    sssd-secrets.service \
-    sssd-secrets.socket \
     sssd.service \
 "
 SYSTEMD_AUTO_ENABLE = "disable"