From 44a4c23f372b5486f3a1994a2315bf044e9b41f1 Mon Sep 17 00:00:00 2001
From: Chris PeBenito Policy for managing user accounts. Virtual Private Networking client Virtual Private Networking client
+Execute VPN clients in the vpnc domain.
+
+Execute VPN clients in the vpnc domain, and
+allow the specified role the vpnc domain.
+
-Allow execution of anonymous mappings, e.g. executable stack.
+Allow making anonymous memory executable, e.g.
+for runtime-code generation or executable stack.
+ -
+ vpn
+
+
@@ -173,6 +176,11 @@ after installation of Red Hat/Fedora systems.
usermanage
+
diff --git a/www/api-docs/admin_acct.html b/www/api-docs/admin_acct.html
index 47669791..0ebc8c1d 100644
--- a/www/api-docs/admin_acct.html
+++ b/www/api-docs/admin_acct.html
@@ -52,6 +52,9 @@
-
usermanage
+
+ vpn
+
+
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_consoletype.html b/www/api-docs/admin_consoletype.html
index 209af268..796337ad 100644
--- a/www/api-docs/admin_consoletype.html
+++ b/www/api-docs/admin_consoletype.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_dmesg.html b/www/api-docs/admin_dmesg.html
index 9edc3439..da7f797d 100644
--- a/www/api-docs/admin_dmesg.html
+++ b/www/api-docs/admin_dmesg.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_firstboot.html b/www/api-docs/admin_firstboot.html
index f9ec0481..c84666a9 100644
--- a/www/api-docs/admin_firstboot.html
+++ b/www/api-docs/admin_firstboot.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_logrotate.html b/www/api-docs/admin_logrotate.html
index 08da1cb2..ff9327ba 100644
--- a/www/api-docs/admin_logrotate.html
+++ b/www/api-docs/admin_logrotate.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_netutils.html b/www/api-docs/admin_netutils.html
index f26a5914..f51f45c7 100644
--- a/www/api-docs/admin_netutils.html
+++ b/www/api-docs/admin_netutils.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_quota.html b/www/api-docs/admin_quota.html
index 4775045d..0cf7629b 100644
--- a/www/api-docs/admin_quota.html
+++ b/www/api-docs/admin_quota.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_rpm.html b/www/api-docs/admin_rpm.html
index a0bae7c8..7e70e155 100644
--- a/www/api-docs/admin_rpm.html
+++ b/www/api-docs/admin_rpm.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_su.html b/www/api-docs/admin_su.html
index 30884d8f..1f63acf8 100644
--- a/www/api-docs/admin_su.html
+++ b/www/api-docs/admin_su.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_sudo.html b/www/api-docs/admin_sudo.html
index be266651..4d635b84 100644
--- a/www/api-docs/admin_sudo.html
+++ b/www/api-docs/admin_sudo.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_tmpreaper.html b/www/api-docs/admin_tmpreaper.html
index 2be113dc..dba0046c 100644
--- a/www/api-docs/admin_tmpreaper.html
+++ b/www/api-docs/admin_tmpreaper.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_updfstab.html b/www/api-docs/admin_updfstab.html
index 3012cacc..94f349dc 100644
--- a/www/api-docs/admin_updfstab.html
+++ b/www/api-docs/admin_updfstab.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_usermanage.html b/www/api-docs/admin_usermanage.html
index f856d862..1f4c0c74 100644
--- a/www/api-docs/admin_usermanage.html
+++ b/www/api-docs/admin_usermanage.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
diff --git a/www/api-docs/admin_vpn.html b/www/api-docs/admin_vpn.html
new file mode 100644
index 00000000..f1cf90a6
--- /dev/null
+++ b/www/api-docs/admin_vpn.html
@@ -0,0 +1,239 @@
+
+
+
+
+ -
+ consoletype
+
+ -
+ dmesg
+
+ -
+ firstboot
+
+ -
+ logrotate
+
+ -
+ netutils
+
+ -
+ quota
+
+ -
+ rpm
+
+ -
+ su
+
+ -
+ sudo
+
+ -
+ tmpreaper
+
+ -
+ updfstab
+
+ -
+ usermanage
+
+ -
+ vpn
+
+
+ * Global Booleans
+
+ * Global Tunables
+
+ * Layer Index
+
+ * Interface Index
+
+ * Template Index
+Layer: admin
+Module: vpn
+
+Description:
+
+Interfaces:
+
+
+
+Summary
+Parameters
+
+
+
+
+Parameter: Description: Optional:
+
+
+domain
+
+
+The type of the process performing this action.
+
+
+No
+
+Summary
+Parameters
+
+
+
+
+Parameter: Description: Optional:
+
+
+domain
+
+
+The type of the process performing this action.
+
+
+No
+
+
+
+role
+
+
+The role to be allowed the vpnc domain.
+
+
+No
+
+
+
+terminal
+
+
+The type of the terminal allow the vpnc domain to use.
+
+
+No
+
+ -
+ vpn
+
+
@@ -106,9 +109,15 @@
-
comsat
+ -
+ cpucontrol
+
-
cron
+ -
+ cvs
+
-
dbus
@@ -136,6 +145,9 @@
-
kerberos
+ -
+ ktalk
+
-
ldap
@@ -154,30 +166,60 @@
-
ntp
+ -
+ portmap
+
+ -
+ postgresql
+
-
privoxy
-
remotelogin
+ -
+ rlogin
+
-
rshd
-
rsync
+ -
+ samba
+
-
sendmail
+ -
+ snmp
+
-
squid
-
ssh
+ -
+ stunnel
+
-
tcpd
+ -
+ telnet
+
+ -
+ tftp
+
+ -
+ uucp
+
+ -
+ zebra
+
+
diff --git a/www/api-docs/global_tunables.html b/www/api-docs/global_tunables.html
index 91c30477..ba986ce3 100644
--- a/www/api-docs/global_tunables.html
+++ b/www/api-docs/global_tunables.html
@@ -52,6 +52,9 @@
-
usermanage
+ -
+ vpn
+
+
@@ -106,9 +109,15 @@
-
comsat
+ -
+ cpucontrol
+
-
cron
+ -
+ cvs
+
-
dbus
@@ -136,6 +145,9 @@
-
kerberos
+ -
+ ktalk
+
-
ldap
@@ -154,30 +166,60 @@
-
ntp
+ -
+ portmap
+
+ -
+ postgresql
+
-
privoxy
-
remotelogin
+ -
+ rlogin
+
-
rshd
-
rsync
+ -
+ samba
+
-
sendmail
+ -
+ snmp
+
-
squid
-
ssh
+ -
+ stunnel
+
-
tcpd
+ -
+ telnet
+
+ -
+ tftp
+
+ -
+ uucp
+
+ -
+ zebra
+
+
@@ -288,7 +330,8 @@
Description
-Support Share libraries with text relocations +Allow making a modified private file +mapping executable (text relocation). +
+ + + +false
+ ++Allow making the stack executable via mprotect. +Also requires allow_execmem.
false
+ ++allow host key based authentication +
+ +false
+ ++Allow applications to read untrusted content +If this is disallowed, Internet content has +to be manually relabeled for read access to be granted +
+ +false
+ ++Allow squid to connect to all ports, not just +HTTP, FTP, and Gopher ports. +
+ +false
- --Allow the use of DNS for name resolution. -
- -false
+ ++Allow applications to write untrusted content +If this is disallowed, no Internet content +will be stored. +
+ +