Global tunables:

allow_execmem
Default value

false

Description

Allow making anonymous memory executable, e.g. for runtime-code generation or executable stack.

allow_execmod
Default value

false

Description

Allow making a modified private file mapping executable (text relocation).

allow_execstack
Default value

false

Description

Allow making the stack executable via mprotect. Also requires allow_execmem.

allow_gpg_execstack
Default value

false

Description

Allow gpg executable stack

allow_kerberos
Default value

false

Description

Allow system to run with kerberos

allow_ssh_keysign
Default value

false

Description

allow host key based authentication

allow_user_mysql_connect
Default value

false

Description

Allow users to connect to mysql

allow_ypbind
Default value

false

Description

Allow system to run with NIS

cron_can_relabel
Default value

false

Description

Allow system cron jobs to relabel filesystem for restoring file contexts.

fcron_crond
Default value

false

Description

Enable extra rules in the cron domain to support fcron.

named_write_master_zones
Default value

false

Description

Allow BIND to write the master zone files. Generally this is used for dynamic DNS.

read_default_t
Default value

false

Description

Allow reading of default_t files.

read_untrusted_content
Default value

false

Description

Allow applications to read untrusted content If this is disallowed, Internet content has to be manually relabeled for read access to be granted

run_ssh_inetd
Default value

false

Description

Allow ssh to run from inetd instead of as a daemon.

squid_connect_any
Default value

false

Description

Allow squid to connect to all ports, not just HTTP, FTP, and Gopher ports.

ssh_sysadm_login
Default value

false

Description

Allow ssh logins as sysadm_r:sysadm_t

staff_read_sysadm_file
Default value

false

Description

Allow staff_r users to search the sysadm home dir and read files (such as ~/.bashrc)

use_nfs_home_dirs
Default value

false

Description

Support NFS home directories

use_samba_home_dirs
Default value

false

Description

Support SAMBA home directories

user_direct_mouse
Default value

false

Description

Allow regular users direct mouse access

user_dmesg
Default value

false

Description

Allow users to read system messages.

user_net_control
Default value

false

Description

Allow users to control network interfaces (also needs USERCTL=true)

user_ping
Default value

false

Description

Control users use of ping and traceroute

user_rw_noexattrfile
Default value

false

Description

Allow user to r/w noextattrfile (FAT, CDROM, FLOPPY)

user_rw_usb
Default value

false

Description

Allow users to rw usb devices

user_tcp_server
Default value

false

Description

Allow users to run TCP servers (bind to ports and accept connection from the same domain and outside users) disabling this forces FTP passive mode and may change other protocols.

user_ttyfile_stat
Default value

false

Description

Allow w to display everyone

write_untrusted_content
Default value

false

Description

Allow applications to write untrusted content If this is disallowed, no Internet content will be stored.