605 lines
7.9 KiB
Plaintext
605 lines
7.9 KiB
Plaintext
# Layer: admin
|
|
# Module: anaconda
|
|
#
|
|
# Policy for the Anaconda installer.
|
|
#
|
|
anaconda = module
|
|
|
|
# Layer: services
|
|
# Module: apache
|
|
#
|
|
# Apache web server
|
|
#
|
|
apache = module
|
|
|
|
# Module: application
|
|
# Required in base
|
|
#
|
|
# Defines attributs and interfaces for all user applications
|
|
#
|
|
application = module
|
|
|
|
# Layer: role
|
|
# Module: auditadm
|
|
#
|
|
# auditadm account on tty logins
|
|
#
|
|
auditadm = module
|
|
|
|
# Layer: system
|
|
# Module: authlogin
|
|
#
|
|
# Common policy for authentication and user login.
|
|
#
|
|
authlogin = module
|
|
|
|
# Layer: services
|
|
# Module: bluetooth
|
|
#
|
|
# Bluetooth tools and system services.
|
|
#
|
|
bluetooth = module
|
|
|
|
# Module: bootloader
|
|
#
|
|
# Policy for the kernel modules, kernel image, and bootloader.
|
|
#
|
|
bootloader = module
|
|
|
|
# Layer: services
|
|
# Module: chronyd
|
|
#
|
|
# Daemon for maintaining clock time
|
|
#
|
|
chronyd = module
|
|
|
|
# Layer: system
|
|
# Module: clock
|
|
#
|
|
# Policy for reading and setting the hardware clock.
|
|
#
|
|
clock = module
|
|
|
|
# Layer: kernel
|
|
# Module: corecommands
|
|
# Required in base
|
|
#
|
|
# Core policy for shells, and generic programs
|
|
# in /bin, /sbin, /usr/bin, and /usr/sbin.
|
|
#
|
|
corecommands = base
|
|
|
|
# Layer: kernel
|
|
# Module: corenetwork
|
|
# Required in base
|
|
#
|
|
# Policy controlling access to network objects
|
|
#
|
|
corenetwork = base
|
|
|
|
# Layer: services
|
|
# Module: cpucontrol
|
|
#
|
|
# Services for loading CPU microcode and CPU frequency scaling.
|
|
#
|
|
cpucontrol = module
|
|
|
|
# Layer: system
|
|
# Module: daemontools
|
|
#
|
|
# Collection of tools for managing UNIX services
|
|
#
|
|
daemontools = module
|
|
|
|
# Layer: services
|
|
# Module: dbus
|
|
#
|
|
# Desktop messaging bus
|
|
#
|
|
dbus = module
|
|
|
|
# Module: devices
|
|
# Required in base
|
|
#
|
|
# Device nodes and interfaces for many basic system devices.
|
|
#
|
|
devices = base
|
|
|
|
# Layer: services
|
|
# Module: dhcp
|
|
#
|
|
# Dynamic host configuration protocol (DHCP) server
|
|
#
|
|
dhcp = module
|
|
|
|
# Layer: admin
|
|
# Module: dmesg
|
|
#
|
|
# Policy for dmesg.
|
|
#
|
|
dmesg = module
|
|
|
|
# Module: domain
|
|
# Required in base
|
|
#
|
|
# Core policy for domains.
|
|
#
|
|
domain = base
|
|
|
|
# Module: files
|
|
# Required in base
|
|
#
|
|
# Basic filesystem types and interfaces.
|
|
#
|
|
files = base
|
|
|
|
# Module: filesystem
|
|
# Required in base
|
|
#
|
|
# Policy for filesystems.
|
|
#
|
|
filesystem = base
|
|
|
|
# Layer: system
|
|
# Module: fstools
|
|
#
|
|
# Tools for filesystem management, such as mkfs and fsck.
|
|
#
|
|
fstools = module
|
|
|
|
# Layer: contrib
|
|
# Module: fwupd
|
|
#
|
|
# fwupd is a daemon to allow session software to update device firmware.
|
|
#
|
|
fwupd = module
|
|
|
|
# Layer: apps
|
|
# Module: games
|
|
#
|
|
# The Open Group Pegasus CIM/WBEM Server.
|
|
#
|
|
games = module
|
|
|
|
# Layer: system
|
|
# Module: getty
|
|
#
|
|
# Policy for getty.
|
|
#
|
|
getty = module
|
|
|
|
# Layer: apps
|
|
# Module: gnome
|
|
#
|
|
# gnome session and gconf
|
|
#
|
|
gnome = module
|
|
|
|
# Layer: apps
|
|
# Module: gpg
|
|
#
|
|
# Policy for GNU Privacy Guard and related programs.
|
|
#
|
|
gpg = module
|
|
|
|
# Layer: system
|
|
# Module: hostname
|
|
#
|
|
# Policy for changing the system host name.
|
|
#
|
|
hostname = module
|
|
|
|
# Layer: system
|
|
# Module: init
|
|
#
|
|
# System initialization programs (init and init scripts).
|
|
#
|
|
init = module
|
|
|
|
# Layer: system
|
|
# Module: ipsec
|
|
#
|
|
# TCP/IP encryption
|
|
#
|
|
ipsec = module
|
|
|
|
# Layer: system
|
|
# Module: iptables
|
|
#
|
|
# Policy for iptables.
|
|
#
|
|
iptables = module
|
|
|
|
# Layer: contrib
|
|
# Module: journalctl
|
|
#
|
|
# journalctl policy
|
|
#
|
|
journalctl = module
|
|
|
|
# Layer: services
|
|
# Module: kerberos
|
|
#
|
|
# MIT Kerberos admin and KDC
|
|
#
|
|
kerberos = module
|
|
|
|
# Module: kernel
|
|
# Required in base
|
|
#
|
|
# Policy for kernel threads, proc filesystem,and unlabeled processes and objects.
|
|
#
|
|
kernel = base
|
|
|
|
# Layer: services
|
|
# Module: ldap
|
|
#
|
|
# OpenLDAP directory server
|
|
#
|
|
ldap = module
|
|
|
|
# Layer: system
|
|
# Module: libraries
|
|
#
|
|
# Policy for system libraries.
|
|
#
|
|
libraries = module
|
|
|
|
# Layer: apps
|
|
# Module: loadkeys
|
|
#
|
|
# Load keyboard mappings.
|
|
#
|
|
loadkeys = module
|
|
|
|
# Layer: system
|
|
# Module: locallogin
|
|
#
|
|
# Policy for local logins.
|
|
#
|
|
locallogin = module
|
|
|
|
# Layer: role
|
|
# Module: logadm
|
|
#
|
|
# Minimally prived root role for managing logging system
|
|
#
|
|
logadm = module
|
|
|
|
# Layer: system
|
|
# Module: logging
|
|
#
|
|
# Policy for the kernel message logger and system logging daemon.
|
|
#
|
|
logging = module
|
|
|
|
# Layer: services
|
|
# Module: lpd
|
|
#
|
|
# Line printer daemon
|
|
#
|
|
lpd = module
|
|
|
|
# Layer: system
|
|
# Module: lvm
|
|
#
|
|
# Policy for logical volume management programs.
|
|
#
|
|
lvm = module
|
|
|
|
# Layer: contrib
|
|
# Module: mandb
|
|
#
|
|
# Policy for mandb
|
|
#
|
|
mandb = module
|
|
|
|
# Module: mcs
|
|
# Required in base
|
|
#
|
|
# MultiCategory security policy
|
|
#
|
|
mcs = base
|
|
|
|
# Layer: system
|
|
# Module: miscfiles
|
|
#
|
|
# Miscelaneous files.
|
|
#
|
|
miscfiles = module
|
|
|
|
# Module: mls
|
|
# Required in base
|
|
#
|
|
# Multilevel security policy
|
|
#
|
|
mls = base
|
|
|
|
# Layer: system
|
|
# Module: modutils
|
|
#
|
|
# Policy for kernel module utilities
|
|
#
|
|
modutils = module
|
|
|
|
# Layer: system
|
|
# Module: mount
|
|
#
|
|
# Policy for mount.
|
|
#
|
|
mount = module
|
|
|
|
# Layer: services
|
|
# Module: mta
|
|
#
|
|
# Policy common to all email tranfer agents.
|
|
#
|
|
mta = module
|
|
|
|
# Layer: apps
|
|
# Module: namespace
|
|
#
|
|
# policy for namespace.init script
|
|
#
|
|
namespace = module
|
|
|
|
# Layer: system
|
|
# Module: netlabel
|
|
#
|
|
# Basic netlabel types and interfaces.
|
|
#
|
|
netlabel = module
|
|
|
|
# Layer: admin
|
|
# Module: netutils
|
|
#
|
|
# Network analysis utilities
|
|
#
|
|
netutils = module
|
|
|
|
# Layer: services
|
|
# Module: networkmanager
|
|
#
|
|
# Manager for dynamically switching between networks.
|
|
#
|
|
networkmanager = module
|
|
|
|
# Layer: services
|
|
# Module: nis
|
|
#
|
|
# Policy for NIS (YP) servers and clients
|
|
#
|
|
nis = module
|
|
|
|
# Layer: services
|
|
# Module: oddjob
|
|
#
|
|
# policy for oddjob
|
|
#
|
|
oddjob = module
|
|
|
|
# Layer: contrib
|
|
# Module: pesign
|
|
#
|
|
# policy for pesign
|
|
#
|
|
pesign = module
|
|
|
|
# Layer: services
|
|
# Module: postgresql
|
|
#
|
|
# PostgreSQL relational database
|
|
#
|
|
postgresql = module
|
|
|
|
# Layer: services
|
|
# Module: rdisc
|
|
#
|
|
# Network router discovery daemon
|
|
#
|
|
rdisc = module
|
|
|
|
# Layer: services
|
|
# Module: rpcbind
|
|
#
|
|
# universal addresses to RPC program number mapper
|
|
#
|
|
rpc = module
|
|
|
|
# Layer: admin
|
|
# Module: rpm
|
|
#
|
|
# Policy for the RPM package manager.
|
|
#
|
|
rpm = module
|
|
|
|
# Layer: role
|
|
# Module: secadm
|
|
#
|
|
# secadm account on tty logins
|
|
#
|
|
secadm = module
|
|
|
|
# Module: selinux
|
|
# Required in base
|
|
#
|
|
# Policy for kernel security interface, in particular, selinuxfs.
|
|
#
|
|
selinux = base
|
|
|
|
# Layer: system
|
|
# Module: selinuxutil
|
|
#
|
|
# Policy for SELinux policy and userland applications.
|
|
#
|
|
selinuxutil = module
|
|
|
|
# Module: setrans
|
|
# Required in base
|
|
#
|
|
# Policy for setrans
|
|
#
|
|
setrans = module
|
|
|
|
# Layer: apps
|
|
# Module: seunshare
|
|
#
|
|
# seunshare executable
|
|
#
|
|
seunshare = module
|
|
|
|
# Layer: services
|
|
# Module: ssh
|
|
#
|
|
# Secure shell client and server policy.
|
|
#
|
|
ssh = module
|
|
|
|
# Layer: services
|
|
# Module: sssd
|
|
#
|
|
# System Security Services Daemon
|
|
#
|
|
sssd = module
|
|
|
|
# Layer: contrib
|
|
# Module: stalld
|
|
#
|
|
# stalld
|
|
#
|
|
stalld = module
|
|
|
|
# Layer: kernel
|
|
# Module: storage
|
|
#
|
|
# Policy controlling access to storage devices
|
|
#
|
|
storage = base
|
|
|
|
# Layer: admin
|
|
# Module: sudo
|
|
#
|
|
# Execute a command with a substitute user
|
|
#
|
|
su = module
|
|
|
|
# Layer: admin
|
|
# Module: sudo
|
|
#
|
|
# Execute a command with a substitute user
|
|
#
|
|
sudo = module
|
|
|
|
# Layer:role
|
|
# Module: sysadm_secadm
|
|
#
|
|
# System Administrator with Security Admin rules
|
|
#
|
|
sysadm = module
|
|
|
|
# Layer:role
|
|
# Module: sysadm_secadm
|
|
#
|
|
# System Administrator with Security Admin rules
|
|
#
|
|
sysadm_secadm = module
|
|
|
|
# Layer: system
|
|
# Module: sysnetwork
|
|
#
|
|
# Policy for network configuration: ifconfig and dhcp client.
|
|
#
|
|
sysnetwork = module
|
|
|
|
# Layer: system
|
|
# Module: systemd
|
|
#
|
|
# Policy for systemd components
|
|
#
|
|
systemd = module
|
|
|
|
# Module: terminal
|
|
# Required in base
|
|
#
|
|
# Policy for terminals.
|
|
#
|
|
terminal = base
|
|
|
|
# Layer: kernel
|
|
# Module: ubac
|
|
#
|
|
#
|
|
#
|
|
ubac = base
|
|
|
|
# Layer: system
|
|
# Module: udev
|
|
#
|
|
# Policy for udev.
|
|
#
|
|
udev = module
|
|
|
|
# Layer: role
|
|
# Module: unconfineduser
|
|
#
|
|
# The unconfined user domain.
|
|
#
|
|
unconfined = module
|
|
|
|
# Layer: role
|
|
# Module: unconfineduser
|
|
#
|
|
# The unconfined user domain.
|
|
#
|
|
unconfineduser = module
|
|
|
|
# Layer: kernel
|
|
# Module: unconfined
|
|
#
|
|
# The unlabelednet module.
|
|
#
|
|
unlabelednet = module
|
|
|
|
# Layer: system
|
|
# Module: userdomain
|
|
#
|
|
# Policy for user domains
|
|
#
|
|
userdomain = module
|
|
|
|
# Layer: apps
|
|
# Module: userhelper
|
|
#
|
|
# A helper interface to pam.
|
|
#
|
|
userhelper = module
|
|
|
|
# Layer: admin
|
|
# Module: usermanage
|
|
#
|
|
# Policy for managing user accounts.
|
|
#
|
|
usermanage = module
|
|
|
|
# Layer: services
|
|
# Module: virt
|
|
#
|
|
# Virtualization libraries
|
|
#
|
|
virt = module
|
|
|
|
# Layer: apps
|
|
# Module: vhostmd
|
|
#
|
|
# vlock - Virtual Console lock program
|
|
#
|
|
vlock = module
|
|
|
|
# Layer: services
|
|
# Module: xserver
|
|
#
|
|
# X windows login display manager
|
|
#
|
|
xserver = module
|
|
|