606 lines
		
	
	
		
			12 KiB
		
	
	
	
		
			HTML
		
	
	
	
	
	
			
		
		
	
	
			606 lines
		
	
	
		
			12 KiB
		
	
	
	
		
			HTML
		
	
	
	
	
	
| <html>
 | |
| <head>
 | |
| <title>
 | |
|  Security Enhanced Linux Reference Policy
 | |
|  </title>
 | |
| <style type="text/css" media="all">@import "style.css";</style>
 | |
| </head>
 | |
| <body>
 | |
| <div id="Header">Security Enhanced Linux Reference Policy</div>
 | |
| <div id='Menu'>
 | |
| 	
 | |
| 		<a href="admin.html">+ 
 | |
| 		admin</a></br/>
 | |
| 		<div id='subitem'>
 | |
| 		
 | |
| 			   - <a href='admin_acct.html'>
 | |
| 			acct</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_consoletype.html'>
 | |
| 			consoletype</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_dmesg.html'>
 | |
| 			dmesg</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_firstboot.html'>
 | |
| 			firstboot</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_logrotate.html'>
 | |
| 			logrotate</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_netutils.html'>
 | |
| 			netutils</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_quota.html'>
 | |
| 			quota</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_rpm.html'>
 | |
| 			rpm</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_su.html'>
 | |
| 			su</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_sudo.html'>
 | |
| 			sudo</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_tmpreaper.html'>
 | |
| 			tmpreaper</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_updfstab.html'>
 | |
| 			updfstab</a><br/>
 | |
| 		
 | |
| 			   - <a href='admin_usermanage.html'>
 | |
| 			usermanage</a><br/>
 | |
| 		
 | |
| 		</div>
 | |
| 	
 | |
| 		<a href="apps.html">+ 
 | |
| 		apps</a></br/>
 | |
| 		<div id='subitem'>
 | |
| 		
 | |
| 			   - <a href='apps_gpg.html'>
 | |
| 			gpg</a><br/>
 | |
| 		
 | |
| 			   - <a href='apps_loadkeys.html'>
 | |
| 			loadkeys</a><br/>
 | |
| 		
 | |
| 		</div>
 | |
| 	
 | |
| 		<a href="kernel.html">+ 
 | |
| 		kernel</a></br/>
 | |
| 		<div id='subitem'>
 | |
| 		
 | |
| 			   - <a href='kernel_bootloader.html'>
 | |
| 			bootloader</a><br/>
 | |
| 		
 | |
| 			   - <a href='kernel_corenetwork.html'>
 | |
| 			corenetwork</a><br/>
 | |
| 		
 | |
| 			   - <a href='kernel_devices.html'>
 | |
| 			devices</a><br/>
 | |
| 		
 | |
| 			   - <a href='kernel_filesystem.html'>
 | |
| 			filesystem</a><br/>
 | |
| 		
 | |
| 			   - <a href='kernel_kernel.html'>
 | |
| 			kernel</a><br/>
 | |
| 		
 | |
| 			   - <a href='kernel_selinux.html'>
 | |
| 			selinux</a><br/>
 | |
| 		
 | |
| 			   - <a href='kernel_storage.html'>
 | |
| 			storage</a><br/>
 | |
| 		
 | |
| 			   - <a href='kernel_terminal.html'>
 | |
| 			terminal</a><br/>
 | |
| 		
 | |
| 		</div>
 | |
| 	
 | |
| 		<a href="services.html">+ 
 | |
| 		services</a></br/>
 | |
| 		<div id='subitem'>
 | |
| 		
 | |
| 			   - <a href='services_bind.html'>
 | |
| 			bind</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_comsat.html'>
 | |
| 			comsat</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_cron.html'>
 | |
| 			cron</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_dbus.html'>
 | |
| 			dbus</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_dhcp.html'>
 | |
| 			dhcp</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_dictd.html'>
 | |
| 			dictd</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_gpm.html'>
 | |
| 			gpm</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_hal.html'>
 | |
| 			hal</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_howl.html'>
 | |
| 			howl</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_inetd.html'>
 | |
| 			inetd</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_inn.html'>
 | |
| 			inn</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_kerberos.html'>
 | |
| 			kerberos</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_ldap.html'>
 | |
| 			ldap</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_mta.html'>
 | |
| 			mta</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_mysql.html'>
 | |
| 			mysql</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_nis.html'>
 | |
| 			nis</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_nscd.html'>
 | |
| 			nscd</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_ntp.html'>
 | |
| 			ntp</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_privoxy.html'>
 | |
| 			privoxy</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_remotelogin.html'>
 | |
| 			remotelogin</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_rshd.html'>
 | |
| 			rshd</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_rsync.html'>
 | |
| 			rsync</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_sendmail.html'>
 | |
| 			sendmail</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_squid.html'>
 | |
| 			squid</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_ssh.html'>
 | |
| 			ssh</a><br/>
 | |
| 		
 | |
| 			   - <a href='services_tcpd.html'>
 | |
| 			tcpd</a><br/>
 | |
| 		
 | |
| 		</div>
 | |
| 	
 | |
| 		<a href="system.html">+ 
 | |
| 		system</a></br/>
 | |
| 		<div id='subitem'>
 | |
| 		
 | |
| 			   - <a href='system_authlogin.html'>
 | |
| 			authlogin</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_clock.html'>
 | |
| 			clock</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_corecommands.html'>
 | |
| 			corecommands</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_domain.html'>
 | |
| 			domain</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_files.html'>
 | |
| 			files</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_fstools.html'>
 | |
| 			fstools</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_getty.html'>
 | |
| 			getty</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_hostname.html'>
 | |
| 			hostname</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_hotplug.html'>
 | |
| 			hotplug</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_init.html'>
 | |
| 			init</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_ipsec.html'>
 | |
| 			ipsec</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_iptables.html'>
 | |
| 			iptables</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_libraries.html'>
 | |
| 			libraries</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_locallogin.html'>
 | |
| 			locallogin</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_logging.html'>
 | |
| 			logging</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_lvm.html'>
 | |
| 			lvm</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_miscfiles.html'>
 | |
| 			miscfiles</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_modutils.html'>
 | |
| 			modutils</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_mount.html'>
 | |
| 			mount</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_pcmcia.html'>
 | |
| 			pcmcia</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_raid.html'>
 | |
| 			raid</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_selinuxutil.html'>
 | |
| 			selinuxutil</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_sysnetwork.html'>
 | |
| 			sysnetwork</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_udev.html'>
 | |
| 			udev</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_unconfined.html'>
 | |
| 			unconfined</a><br/>
 | |
| 		
 | |
| 			   - <a href='system_userdomain.html'>
 | |
| 			userdomain</a><br/>
 | |
| 		
 | |
| 		</div>
 | |
| 	
 | |
| 	<br/><p/>
 | |
| 	<a href="global_booleans.html">* Global Booleans </a>
 | |
| 	<br/><p/>
 | |
| 	<a href="global_tunables.html">* Global Tunables </a>
 | |
| 	<p/><br/><p/>
 | |
| 	<a href="index.html">* Layer Index</a>
 | |
| 	<br/><p/>
 | |
| 	<a href="interfaces.html">* Interface Index</a>
 | |
| 	<br/><p/>
 | |
| 	<a href="templates.html">* Template Index</a>
 | |
| </div>
 | |
| 
 | |
| <div id="Content">
 | |
| <h3>Global tunables:</h3>
 | |
| 
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">allow_execmem</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow execution of anonymous mappings, e.g. executable stack.
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">allow_execmod</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Support Share libraries with text relocations
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">allow_gpg_execstack</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow gpg executable stack
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">allow_kerberos</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow system to run with kerberos
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">allow_user_mysql_connect</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow users to connect to mysql
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">allow_ypbind</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow system to run with NIS
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">cron_can_relabel</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow system cron jobs to relabel filesystem
 | |
| for restoring file contexts.
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">fcron_crond</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Enable extra rules in the cron domain
 | |
| to support fcron.
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">named_write_master_zones</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow BIND to write the master zone files.
 | |
| Generally this is used for dynamic DNS.
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">read_default_t</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow reading of default_t files.
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">run_ssh_inetd</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow ssh to run from inetd instead of as a daemon.
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">ssh_sysadm_login</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow ssh logins as sysadm_r:sysadm_t
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">staff_read_sysadm_file</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow staff_r users to search the sysadm home 
 | |
| dir and read files (such as ~/.bashrc)
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">use_dns</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow the use of DNS for name resolution.
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">use_nfs_home_dirs</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Support NFS home directories
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">use_samba_home_dirs</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Support SAMBA home directories
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">user_direct_mouse</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow regular users direct mouse access 
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">user_dmesg</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow users to read system messages.
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">user_net_control</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow users to control network interfaces
 | |
| (also needs USERCTL=true)
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">user_ping</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Control users use of ping and traceroute
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">user_rw_noexattrfile</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow user to r/w noextattrfile (FAT, CDROM, FLOPPY)
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">user_rw_usb</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow users to rw usb devices
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">user_tcp_server</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow users to run TCP servers (bind to ports and accept connection from
 | |
| the same domain and outside users)  disabling this forces FTP passive mode
 | |
| and may change other protocols.
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| <div id="interface">
 | |
| <div id="codeblock">user_ttyfile_stat</div>
 | |
| <div id="description">
 | |
| <h5>Default value</h5>
 | |
| <p>false</p>
 | |
| 
 | |
| <h5>Description</h5>
 | |
| <p><p>
 | |
| Allow w to display everyone
 | |
| </p></p>
 | |
| 
 | |
| </div></div>
 | |
| 
 | |
| 
 | |
| </div>
 | |
| </body>
 | |
| </html>
 |