diff --git a/.gitignore b/.gitignore
index 8efb055..e6ade51 100644
--- a/.gitignore
+++ b/.gitignore
@@ -262,3 +262,5 @@ serefpolicy*
 /selinux-policy-370bcfb.tar.gz
 /selinux-policy-4b1f9bd.tar.gz
 /selinux-policy-contrib-d2dd0ad.tar.gz
+/selinux-policy-contrib-7ecfe28.tar.gz
+/selinux-policy-116b85e.tar.gz
diff --git a/selinux-policy.spec b/selinux-policy.spec
index 27fcb87..9f19df3 100644
--- a/selinux-policy.spec
+++ b/selinux-policy.spec
@@ -1,11 +1,11 @@
 # github repo with selinux-policy base sources
 %global git0 https://github.com/fedora-selinux/selinux-policy
-%global commit0 4b1f9bdcc030b57ec7e714768450d3c5feadf276
+%global commit0 116b85e97e58ba673c77b67766fe8807a0100a0e
 %global shortcommit0 %(c=%{commit0}; echo ${c:0:7})
 
 # github repo with selinux-policy contrib sources
 %global git1 https://github.com/fedora-selinux/selinux-policy-contrib
-%global commit1 d2dd0adcc8bc01f7cd1c6b31f2159bdf40912def
+%global commit1 7ecfe283d8c85cf9c6da289b9b511ab95b1d3c36
 %global shortcommit1 %(c=%{commit1}; echo ${c:0:7})
 
 %define distro redhat
@@ -29,7 +29,7 @@
 Summary: SELinux policy configuration
 Name: selinux-policy
 Version: 3.14.2
-Release: 7%{?dist}
+Release: 8%{?dist}
 License: GPLv2+
 Group: System Environment/Base
 Source: %{git0}/archive/%{commit0}/%{name}-%{shortcommit0}.tar.gz
@@ -714,6 +714,12 @@ exit 0
 %endif
 
 %changelog
+* Wed Mar 21 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.2-8
+- Improve bluetooth_stream_socket interface to allow caller domain also send bluetooth sockets
+- Allow tcpd_t bind on sshd_port_t if ssh_use_tcpd() is enabled
+- Allow semanage_t domain mmap usr_t files
+- Add new boolean: ssh_use_tcpd()
+
 * Tue Mar 20 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.2-7
 - Update screen_role_template() to allow also creating sockets in HOMEDIR/screen/
 - Allow newrole_t dacoverride capability
diff --git a/sources b/sources
index c16a7a7..811b300 100644
--- a/sources
+++ b/sources
@@ -1,3 +1,3 @@
-SHA512 (selinux-policy-4b1f9bd.tar.gz) = 8d86d4a273985bd654cebe90f70a4c50b57e37fd271d556e6f6cc12cdc1d33205435266a35b28dca682d06e522b0f2d8a49a8470faeefcf6e0bc61593ed8e9fd
-SHA512 (selinux-policy-contrib-d2dd0ad.tar.gz) = 25372e3afddd5e6457221884158b50ea7dedbafbc0466b85f333f8c5e90eb79a0ea3cedcb68e37173a67ed13a26997aa0d23703f735f450bd604fabff2e970bc
-SHA512 (container-selinux.tgz) = f0e27e4eae5d6b516e0d4add5c476960c98be0dd25318a9986a52cd698508d6719f5da01b41e125e4195e22fd1bd3288f69b3b531d07bad1ed3fc4ed2aa0e6a0
+SHA512 (selinux-policy-contrib-7ecfe28.tar.gz) = 0dd8ad461e3442fabe3cc1b5852f512d265f6eaca6a2f62623a61ee645a1addadea4d0892b9ed6df09be6e9a3f91a103b292be14b04d2666c794a74a5017a447
+SHA512 (selinux-policy-116b85e.tar.gz) = e5b3f9ed20603e6fa3e2a4b7e50deaaf3202672a99e889194d67a6c2dfd00521fb087701551754dda5905fe81f80c7dd29ff1655c4882c26b5b9a5227198e7a6
+SHA512 (container-selinux.tgz) = 65467e6d7afef429a19506dcad5f904b39f5ae9e5d089b5d3cf1560f35a3107ea61f6d0bd8326c1416f1b6264c1ee84ead29e32a65993dc70a726f5fa5811d3a