Chris PeBenito e3a8e3
<html>
Chris PeBenito e3a8e3
<head>
Chris PeBenito e3a8e3
<title>
Chris PeBenito e3a8e3
 Security Enhanced Linux Reference Policy
Chris PeBenito e3a8e3
 </title>
Chris PeBenito e3a8e3
<style type="text/css" media="all">@import "style.css";</style>
Chris PeBenito e3a8e3
</head>
Chris PeBenito e3a8e3
<body>
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		admin
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		apps
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		kernel
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		services
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
			   - 
Chris PeBenito e3a8e3
			cron
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
			   - 
Chris PeBenito e3a8e3
			inetd
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
			   - 
Chris PeBenito e3a8e3
			kerberos
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
			   - 
Chris PeBenito e3a8e3
			mta
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
			   - 
Chris PeBenito e3a8e3
			nis
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
			   - 
Chris PeBenito e3a8e3
			remotelogin
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
			   - 
Chris PeBenito e3a8e3
			sendmail
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
			   - 
Chris PeBenito e3a8e3
			ssh
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		system
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
	

Chris PeBenito e3a8e3
	* Interface Index
Chris PeBenito e3a8e3
	

Chris PeBenito e3a8e3
	* Template Index
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3

Layer: services

Chris PeBenito e3a8e3

Module: ssh

Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Interfaces
Chris PeBenito e3a8e3
Templates
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3

Description:

Chris PeBenito e3a8e3
Chris PeBenito 767266

Secure shell client and server policy.

Chris PeBenito 767266
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3

Interfaces:

Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
ssh_dontaudit_read_server_keys(
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		domain
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
	)
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Summary
Chris PeBenito e3a8e3

Read ssh server keys

Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Parameters
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Parameter:Description:Optional:
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
domain
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
The type of the process performing this action.
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
No
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Return
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3

Templates:

Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
ssh_per_userdomain_template(
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		userdomain_prefix
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
	)
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Summary
Chris PeBenito e3a8e3

Chris PeBenito e3a8e3
The per user domain template for the ssh module.
Chris PeBenito e3a8e3

Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Description
Chris PeBenito e3a8e3

Chris PeBenito e3a8e3

Chris PeBenito e3a8e3
This template creates a derived domains which are used
Chris PeBenito e3a8e3
for ssh client sessions and user ssh agents.  A derived
Chris PeBenito e3a8e3
type is also created to protect the user ssh keys.
Chris PeBenito e3a8e3

Chris PeBenito e3a8e3

Chris PeBenito e3a8e3
This template is invoked automatically for each user, and
Chris PeBenito e3a8e3
generally does not need to be invoked directly
Chris PeBenito e3a8e3
by policy writers.
Chris PeBenito e3a8e3

Chris PeBenito e3a8e3

Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Parameters
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Parameter:Description:Optional:
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
userdomain_prefix
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
The prefix of the user domain (e.g., user
Chris PeBenito e3a8e3
is the prefix for user_t).
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
No
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
ssh_server_template(
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		userdomain_prefix
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
	
Chris PeBenito e3a8e3
	)
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Summary
Chris PeBenito e3a8e3

Chris PeBenito e3a8e3
The template to define a ssh server.
Chris PeBenito e3a8e3

Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Description
Chris PeBenito e3a8e3

Chris PeBenito e3a8e3

Chris PeBenito e3a8e3
This template creates a domains to be used for
Chris PeBenito e3a8e3
creating a ssh server.  This is typically done
Chris PeBenito e3a8e3
to have multiple ssh servers of different sensitivities,
Chris PeBenito e3a8e3
such as for an internal network-facing ssh server, and
Chris PeBenito e3a8e3
a external network-facing ssh server.
Chris PeBenito e3a8e3

Chris PeBenito e3a8e3

Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Parameters
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Parameter:Description:Optional:
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
userdomain_prefix
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
The prefix of the server domain (e.g., sshd
Chris PeBenito e3a8e3
is the prefix for sshd_t).
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
No
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Return
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
</body>
Chris PeBenito e3a8e3
</html>