2005-10-07 18:08:50 +00:00
|
|
|
#
|
|
|
|
# This file is for the declaration of global booleans.
|
|
|
|
# To change the default value at build time, the booleans.conf
|
|
|
|
# file should be used.
|
|
|
|
#
|
|
|
|
|
2006-07-28 15:13:58 +00:00
|
|
|
ifdef(`strict_policy',`
|
2006-02-10 18:41:53 +00:00
|
|
|
## <desc>
|
|
|
|
## <p>
|
2005-10-07 18:08:50 +00:00
|
|
|
## Enabling secure mode disallows programs, such as
|
|
|
|
## newrole, from transitioning to administrative
|
|
|
|
## user domains.
|
2006-02-10 18:41:53 +00:00
|
|
|
## </p>
|
|
|
|
## </desc>
|
2005-10-07 18:08:50 +00:00
|
|
|
gen_bool(secure_mode,false)
|
2006-07-28 15:13:58 +00:00
|
|
|
')
|
2005-11-07 20:09:28 +00:00
|
|
|
|
2006-02-10 18:41:53 +00:00
|
|
|
## <desc>
|
|
|
|
## <p>
|
2005-11-07 20:09:28 +00:00
|
|
|
## Disable transitions to insmod.
|
2006-02-10 18:41:53 +00:00
|
|
|
## </p>
|
|
|
|
## </desc>
|
2005-11-07 20:09:28 +00:00
|
|
|
gen_bool(secure_mode_insmod,false)
|
|
|
|
|
2006-02-10 18:41:53 +00:00
|
|
|
## <desc>
|
|
|
|
## <p>
|
2005-11-07 20:09:28 +00:00
|
|
|
## boolean to determine whether the system permits loading policy, setting
|
|
|
|
## enforcing mode, and changing boolean values. Set this to true and you
|
|
|
|
## have to reboot to set it back
|
2006-02-10 18:41:53 +00:00
|
|
|
## </p>
|
|
|
|
## </desc>
|
2005-11-07 20:09:28 +00:00
|
|
|
gen_bool(secure_mode_policyload,false)
|