define(`can_kerberos',` ifdef(`kerberos.te',` if (allow_kerberos) { can_network_client($1, `kerberos_port_t') allow $1 kerberos_port_t:tcp_socket name_connect; can_resolve($1) } ') dnl kerberos.te dontaudit $1 krb5_conf_t:file write; allow $1 krb5_conf_t:file { getattr read }; ')