false
Allow execution of anonymous mappings, e.g. executable stack.
false
Support Share libraries with text relocations
false
Allow gpg executable stack
false
Allow system to run with kerberos
false
Allow users to connect to mysql
false
Allow system to run with NIS
false
Allow system cron jobs to relabel filesystem for restoring file contexts.
false
Enable extra rules in the cron domain to support fcron.
false
Allow BIND to write the master zone files. Generally this is used for dynamic DNS.
false
Allow reading of default_t files.
false
Allow ssh to run from inetd instead of as a daemon.
false
Allow ssh logins as sysadm_r:sysadm_t
false
Allow staff_r users to search the sysadm home dir and read files (such as ~/.bashrc)
false
Allow the use of DNS for name resolution.
false
Support NFS home directories
false
Support SAMBA home directories
false
Allow regular users direct mouse access
false
Allow users to read system messages.
false
Allow users to control network interfaces (also needs USERCTL=true)
false
Control users use of ping and traceroute
false
Allow user to r/w noextattrfile (FAT, CDROM, FLOPPY)
false
Allow users to rw usb devices
false
Allow users to run TCP servers (bind to ports and accept connection from the same domain and outside users) disabling this forces FTP passive mode and may change other protocols.
false
Allow w to display everyone