selinux-policy/man/man8/kerberos_selinux.8

36 lines
1.2 KiB
Groff
Raw Normal View History

2006-01-06 22:51:40 +00:00
.TH "kerberos_selinux" "8" "17 Jan 2005" "dwalsh@redhat.com" "kerberos Selinux Policy documentation"
.de EX
.nf
.ft CW
..
.de EE
.ft R
.fi
..
2006-01-06 22:51:40 +00:00
.SH "NAME"
kerberos_selinux \- Security Enhanced Linux Policy for Kerberos.
.SH "DESCRIPTION"
Security-Enhanced Linux secures the system via flexible mandatory access
control. By default Kerberos access is not allowed, since it requires daemons to be allowed greater access to certain secure files and addtional access to the network.
.SH BOOLEANS
.PP
2006-01-06 22:51:40 +00:00
You must set the allow_kerberos boolean to allow your system to work properly in a Kerberos environment.
.EX
2006-01-06 22:51:40 +00:00
setsebool -P allow_kerberos 1
.EE
2006-01-06 22:51:40 +00:00
If you are running Kerberos daemons kadmind or krb5kdc you can disable the SELinux protection on these daemons by setting the krb5kdc_disable_trans and kadmind_disable_trans booleans.
.EX
2006-01-06 22:51:40 +00:00
setsebool -P krb5kdc_disable_trans 1
service krb5kdc restart
2007-02-26 20:44:35 +00:00
setsebool -P kadmind_disable_trans 1
2006-01-06 22:51:40 +00:00
service kadmind restart
.EE
.PP
2006-01-06 22:51:40 +00:00
system-config-securitylevel is a GUI tool available to customize SELinux policy settings.
.SH AUTHOR
This manual page was written by Dan Walsh <dwalsh@redhat.com>.
.SH "SEE ALSO"
selinux(8), kerberos(1), chcon(1), setsebool(8)