diff --git a/.gitignore b/.gitignore
index f9ffba8..656c76a 100644
--- a/.gitignore
+++ b/.gitignore
@@ -1,3 +1,3 @@
 SOURCES/container-selinux.tgz
-SOURCES/selinux-policy-0fdab31.tar.gz
+SOURCES/selinux-policy-33fd484.tar.gz
 SOURCES/selinux-policy-contrib-4beb213.tar.gz
diff --git a/.selinux-policy.metadata b/.selinux-policy.metadata
index 38532f1..36c1b3a 100644
--- a/.selinux-policy.metadata
+++ b/.selinux-policy.metadata
@@ -1,3 +1,3 @@
-a810a49ab0aa8e61bfcee594ad56807758cf2ad5 SOURCES/container-selinux.tgz
-7a2a9dda6f2b41c7c43cbf48d6ac20d4973608ad SOURCES/selinux-policy-0fdab31.tar.gz
+99c5dc0dbb5f824b2cc29d18e8911401677e0bb1 SOURCES/container-selinux.tgz
+4da13e377b1e178962423475a04832ed39581394 SOURCES/selinux-policy-33fd484.tar.gz
 45d3dbd0265f43953376baacdbc070a566eb429b SOURCES/selinux-policy-contrib-4beb213.tar.gz
diff --git a/SPECS/selinux-policy.spec b/SPECS/selinux-policy.spec
index e6d79f5..fc9caf0 100644
--- a/SPECS/selinux-policy.spec
+++ b/SPECS/selinux-policy.spec
@@ -1,6 +1,6 @@
 # github repo with selinux-policy base sources
 %global git0 https://github.com/fedora-selinux/selinux-policy
-%global commit0 0fdab319c4d575686903933c72efcad405402514
+%global commit0 33fd4847deb2522105cfba82da5efb707025934c
 %global shortcommit0 %(c=%{commit0}; echo ${c:0:7})
 
 # github repo with selinux-policy contrib sources
@@ -29,7 +29,7 @@
 Summary: SELinux policy configuration
 Name: selinux-policy
 Version: 3.14.3
-Release: 64%{?dist}
+Release: 65%{?dist}
 License: GPLv2+
 Source: %{git0}/archive/%{commit0}/%{name}-%{shortcommit0}.tar.gz
 Source29: %{git1}/archive/%{commit1}/%{name}-contrib-%{shortcommit1}.tar.gz
@@ -715,6 +715,10 @@ exit 0
 %endif
 
 %changelog
+* Mon Feb 22 2021 Zdenek Pytela <zpytela@redhat.com> - 3.14.3-65
+- Relabel /usr/sbin/charon-systemd as ipsec_exec_t
+Resolves: rhbz#1889542
+
 * Wed Feb 17 2021 Zdenek Pytela <zpytela@redhat.com> - 3.14.3-64
 - Allow unconfined_t and kprop_t to create krb5_0.rcache2 with the right context
 Resolves: rhbz#1874527