selinux-policy/refpolicy/policy/modules.conf.targeted_example

407 lines
5.7 KiB
Plaintext
Raw Normal View History

#
# This file contains a listing of available modules.
# To prevent a module from being used in policy
# creation, set the module name to "off".
#
# For monolithic policies, modules set to "base" and "module"
# will be built into the policy.
#
# For modular policies, modules set to "base" will be
# included in the base module. "module" will be compiled
# as individual loadable modules.
#
# Layer: kernel
# Module: filesystem
# Required in base
#
# Policy for filesystems.
#
filesystem = base
# Layer: kernel
# Module: selinux
# Required in base
#
# Policy for kernel security interface, in particular, selinuxfs.
#
selinux = base
# Layer: kernel
# Module: kernel
# Required in base
#
# Policy for kernel threads, proc filesystem,and unlabeled processes and objects.
#
kernel = base
# Layer: kernel
# Module: corenetwork
# Required in base
#
# Policy controlling access to network objects
#
corenetwork = base
# Layer: system
# Module: files
# Required in base
#
# Basic filesystem types and interfaces.
#
files = base
# Layer: system
# Module: domain
# Required in base
#
# Core policy for domains.
#
domain = base
2005-08-08 21:03:23 +00:00
# Layer: admin
# Module: usermanage
#
# Policy for managing user accounts.
#
usermanage = base
# Layer: admin
# Module: rpm
#
# Policy for the RPM package manager.
#
rpm = off
# Layer: admin
# Module: dmesg
#
# Policy for dmesg.
#
dmesg = base
# Layer: admin
# Module: logrotate
#
# Rotate and archive system logs
#
logrotate = off
# Layer: admin
# Module: consoletype
#
# Determine of the console connected to the controlling terminal.
#
consoletype = base
# Layer: admin
# Module: netutils
#
# Network analysis utilities
#
netutils = base
# Layer: admin
2005-08-08 21:03:23 +00:00
# Module: acct
#
2005-08-08 21:03:23 +00:00
# Berkeley process accounting
#
2005-08-08 21:03:23 +00:00
acct = base
# Layer: admin
2005-08-08 21:03:23 +00:00
# Module: tmpreaper
#
2005-08-08 21:03:23 +00:00
# Manage temporary directory sizes and file ages
#
2005-08-08 21:03:23 +00:00
tmpreaper = base
# Layer: admin
2005-08-08 21:03:23 +00:00
# Module: updfstab
#
2005-08-08 21:03:23 +00:00
# Red Hat utility to change /etc/fstab.
#
2005-08-08 21:03:23 +00:00
updfstab = base
# Layer: admin
2005-08-08 21:03:23 +00:00
# Module: su
#
2005-08-08 21:03:23 +00:00
# Run shells with substitute user and group
#
2005-08-08 21:03:23 +00:00
su = off
# Layer: apps
# Module: gpg
#
# Policy for GNU Privacy Guard and related programs.
#
gpg = off
# Layer: kernel
# Module: devices
#
# Device nodes and interfaces for many basic system devices.
#
devices = base
# Layer: kernel
# Module: bootloader
#
# Policy for the kernel modules, kernel image, and bootloader.
#
bootloader = base
# Layer: kernel
# Module: storage
#
# Policy controlling access to storage devices
#
storage = base
# Layer: kernel
# Module: terminal
#
# Policy for terminals.
#
terminal = base
# Layer: services
2005-08-08 21:03:23 +00:00
# Module: remotelogin
#
2005-08-08 21:03:23 +00:00
# Policy for rshd, rlogind, and telnetd.
#
2005-08-08 21:03:23 +00:00
remotelogin = base
# Layer: services
2005-08-08 21:03:23 +00:00
# Module: nscd
#
2005-08-08 21:03:23 +00:00
# Name service cache daemon
#
2005-08-08 21:03:23 +00:00
nscd = base
# Layer: services
2005-08-08 21:03:23 +00:00
# Module: nis
#
2005-08-08 21:03:23 +00:00
# Policy for NIS (YP) servers and clients
#
2005-08-08 21:03:23 +00:00
nis = base
# Layer: services
# Module: sendmail
#
# Policy for sendmail.
#
sendmail = off
# Layer: services
2005-08-08 21:03:23 +00:00
# Module: ssh
#
2005-08-08 21:03:23 +00:00
# Secure shell client and server policy.
#
2005-08-08 21:03:23 +00:00
ssh = off
# Layer: services
2005-08-08 21:03:23 +00:00
# Module: cron
#
2005-08-08 21:03:23 +00:00
# Periodic execution of scheduled commands.
#
2005-08-08 21:03:23 +00:00
cron = base
# Layer: services
# Module: inetd
#
# Internet services daemon.
#
inetd = base
# Layer: services
# Module: kerberos
#
# MIT Kerberos admin and KDC
#
kerberos = base
# Layer: services
2005-08-08 21:03:23 +00:00
# Module: mta
#
2005-08-08 21:03:23 +00:00
# Policy common to all email tranfer agents.
#
2005-08-08 21:03:23 +00:00
mta = base
# Layer: services
# Module: mysql
#
# Policy for MySQL
#
mysql = base
# Layer: system
# Module: unconfined
#
# The unconfined domain.
#
unconfined = base
# Layer: system
# Module: authlogin
#
# Common policy for authentication and user login.
#
authlogin = base
# Layer: system
# Module: selinuxutil
#
# Policy for SELinux policy and userland applications.
#
selinuxutil = base
# Layer: system
# Module: getty
#
# Policy for getty.
#
getty = base
# Layer: system
# Module: mount
#
# Policy for mount.
#
mount = base
# Layer: system
2005-08-08 21:03:23 +00:00
# Module: ipsec
#
2005-08-08 21:03:23 +00:00
# TCP/IP encryption
#
2005-08-08 21:03:23 +00:00
ipsec = base
# Layer: system
# Module: locallogin
#
# Policy for local logins.
#
locallogin = base
2005-08-08 21:03:23 +00:00
# Layer: system
# Module: logging
#
# Policy for the kernel message logger and system logging daemon.
#
logging = base
# Layer: system
# Module: sysnetwork
#
# Policy for network configuration: ifconfig and dhcp client.
#
sysnetwork = base
2005-08-08 21:03:23 +00:00
# Layer: system
# Module: fstools
#
# Tools for filesystem management, such as mkfs and fsck.
#
fstools = base
# Layer: system
# Module: pcmcia
#
# PCMCIA card management services
#
pcmcia = base
# Layer: system
# Module: iptables
#
# Policy for iptables.
#
iptables = base
# Layer: system
# Module: userdomain
#
# Policy for user domains
#
userdomain = base
# Layer: system
# Module: corecommands
#
# Core policy for shells, and generic programs
# in /bin, /sbin, /usr/bin, and /usr/sbin.
#
corecommands = base
# Layer: system
# Module: hotplug
#
# Policy for hotplug system, for supporting the
# connection and disconnection of devices at runtime.
#
hotplug = base
2005-08-08 21:03:23 +00:00
# Layer: system
# Module: clock
#
# Policy for reading and setting the hardware clock.
#
clock = base
# Layer: system
# Module: lvm
#
# Policy for logical volume management programs.
#
lvm = base
# Layer: system
# Module: modutils
#
# Policy for kernel module utilities
#
modutils = base
# Layer: system
2005-08-08 21:03:23 +00:00
# Module: init
#
2005-08-08 21:03:23 +00:00
# System initialization programs (init and init scripts).
#
2005-08-08 21:03:23 +00:00
init = base
# Layer: system
2005-08-08 21:03:23 +00:00
# Module: udev
#
2005-08-08 21:03:23 +00:00
# Policy for udev.
#
2005-08-08 21:03:23 +00:00
udev = base
# Layer: system
# Module: hostname
#
# Policy for changing the system host name.
#
hostname = base
# Layer: system
2005-08-08 21:03:23 +00:00
# Module: raid
#
2005-08-08 21:03:23 +00:00
# RAID array management tools
#
2005-08-08 21:03:23 +00:00
raid = base
# Layer: system
# Module: libraries
#
# Policy for system libraries.
#
libraries = base
# Layer: system
# Module: miscfiles
#
# Miscelaneous files.
#
miscfiles = base