Blob Blame History Raw
<html>
<head>
<title>
 Security Enhanced Linux Reference Policy
 </title>
<style type="text/css" media="all">@import "style.css";</style>
</head>
<body>
<div id="Header">Security Enhanced Linux Reference Policy</div>
<div id='Menu'>
	
		<a href="admin.html">+&nbsp;
		admin</a></br/>
		<div id='subitem'>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_acct.html'>
			acct</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_alsa.html'>
			alsa</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_amanda.html'>
			amanda</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_anaconda.html'>
			anaconda</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_bootloader.html'>
			bootloader</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_certwatch.html'>
			certwatch</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_consoletype.html'>
			consoletype</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_ddcprobe.html'>
			ddcprobe</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_dmesg.html'>
			dmesg</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_dmidecode.html'>
			dmidecode</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_firstboot.html'>
			firstboot</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_kudzu.html'>
			kudzu</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_logrotate.html'>
			logrotate</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_logwatch.html'>
			logwatch</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_mrtg.html'>
			mrtg</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_netutils.html'>
			netutils</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_portage.html'>
			portage</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_prelink.html'>
			prelink</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_quota.html'>
			quota</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_readahead.html'>
			readahead</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_rpm.html'>
			rpm</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_su.html'>
			su</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_sudo.html'>
			sudo</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_tmpreaper.html'>
			tmpreaper</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_updfstab.html'>
			updfstab</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_usbmodules.html'>
			usbmodules</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_usermanage.html'>
			usermanage</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_vbetool.html'>
			vbetool</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_vpn.html'>
			vpn</a><br/>
		
		</div>
	
		<a href="apps.html">+&nbsp;
		apps</a></br/>
		<div id='subitem'>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_cdrecord.html'>
			cdrecord</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_gpg.html'>
			gpg</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_irc.html'>
			irc</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_java.html'>
			java</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_loadkeys.html'>
			loadkeys</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_lockdev.html'>
			lockdev</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_mono.html'>
			mono</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_screen.html'>
			screen</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_slocate.html'>
			slocate</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_tvtime.html'>
			tvtime</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_uml.html'>
			uml</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_userhelper.html'>
			userhelper</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_usernetctl.html'>
			usernetctl</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_webalizer.html'>
			webalizer</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_wine.html'>
			wine</a><br/>
		
		</div>
	
		<a href="kernel.html">+&nbsp;
		kernel</a></br/>
		<div id='subitem'>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_corecommands.html'>
			corecommands</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_corenetwork.html'>
			corenetwork</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_devices.html'>
			devices</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_domain.html'>
			domain</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_files.html'>
			files</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_filesystem.html'>
			filesystem</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_kernel.html'>
			kernel</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_mcs.html'>
			mcs</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_mls.html'>
			mls</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_selinux.html'>
			selinux</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_storage.html'>
			storage</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_terminal.html'>
			terminal</a><br/>
		
		</div>
	
		<a href="services.html">+&nbsp;
		services</a></br/>
		<div id='subitem'>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_apache.html'>
			apache</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_apm.html'>
			apm</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_arpwatch.html'>
			arpwatch</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_automount.html'>
			automount</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_avahi.html'>
			avahi</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_bind.html'>
			bind</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_bluetooth.html'>
			bluetooth</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_canna.html'>
			canna</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_comsat.html'>
			comsat</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_cpucontrol.html'>
			cpucontrol</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_cron.html'>
			cron</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_cups.html'>
			cups</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_cvs.html'>
			cvs</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_cyrus.html'>
			cyrus</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_dbskk.html'>
			dbskk</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_dbus.html'>
			dbus</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_dhcp.html'>
			dhcp</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_dictd.html'>
			dictd</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_distcc.html'>
			distcc</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_djbdns.html'>
			djbdns</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_dovecot.html'>
			dovecot</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_fetchmail.html'>
			fetchmail</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_finger.html'>
			finger</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_ftp.html'>
			ftp</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_gpm.html'>
			gpm</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_hal.html'>
			hal</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_howl.html'>
			howl</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_i18n_input.html'>
			i18n_input</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_inetd.html'>
			inetd</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_inn.html'>
			inn</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_irqbalance.html'>
			irqbalance</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_kerberos.html'>
			kerberos</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_ktalk.html'>
			ktalk</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_ldap.html'>
			ldap</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_lpd.html'>
			lpd</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_mailman.html'>
			mailman</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_mta.html'>
			mta</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_mysql.html'>
			mysql</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_networkmanager.html'>
			networkmanager</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_nis.html'>
			nis</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_nscd.html'>
			nscd</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_ntp.html'>
			ntp</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_openct.html'>
			openct</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_pegasus.html'>
			pegasus</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_portmap.html'>
			portmap</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_postfix.html'>
			postfix</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_postgresql.html'>
			postgresql</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_ppp.html'>
			ppp</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_privoxy.html'>
			privoxy</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_procmail.html'>
			procmail</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_publicfile.html'>
			publicfile</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_radius.html'>
			radius</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_radvd.html'>
			radvd</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_rdisc.html'>
			rdisc</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_remotelogin.html'>
			remotelogin</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_rlogin.html'>
			rlogin</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_roundup.html'>
			roundup</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_rpc.html'>
			rpc</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_rshd.html'>
			rshd</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_rsync.html'>
			rsync</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_samba.html'>
			samba</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_sasl.html'>
			sasl</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_sendmail.html'>
			sendmail</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_slrnpull.html'>
			slrnpull</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_smartmon.html'>
			smartmon</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_snmp.html'>
			snmp</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_spamassassin.html'>
			spamassassin</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_squid.html'>
			squid</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_ssh.html'>
			ssh</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_stunnel.html'>
			stunnel</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_sysstat.html'>
			sysstat</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_tcpd.html'>
			tcpd</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_telnet.html'>
			telnet</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_tftp.html'>
			tftp</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_timidity.html'>
			timidity</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_ucspitcp.html'>
			ucspitcp</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_uucp.html'>
			uucp</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_xfs.html'>
			xfs</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_xserver.html'>
			xserver</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_zebra.html'>
			zebra</a><br/>
		
		</div>
	
		<a href="system.html">+&nbsp;
		system</a></br/>
		<div id='subitem'>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_authlogin.html'>
			authlogin</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_clock.html'>
			clock</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_daemontools.html'>
			daemontools</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_fstools.html'>
			fstools</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_getty.html'>
			getty</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_hostname.html'>
			hostname</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_hotplug.html'>
			hotplug</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_init.html'>
			init</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_ipsec.html'>
			ipsec</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_iptables.html'>
			iptables</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_libraries.html'>
			libraries</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_locallogin.html'>
			locallogin</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_logging.html'>
			logging</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_lvm.html'>
			lvm</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_miscfiles.html'>
			miscfiles</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_modutils.html'>
			modutils</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_mount.html'>
			mount</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_pcmcia.html'>
			pcmcia</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_raid.html'>
			raid</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_selinuxutil.html'>
			selinuxutil</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_sysnetwork.html'>
			sysnetwork</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_udev.html'>
			udev</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_unconfined.html'>
			unconfined</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_userdomain.html'>
			userdomain</a><br/>
		
		</div>
	
	<br/><p/>
	<a href="global_booleans.html">*&nbsp;Global&nbsp;Booleans&nbsp;</a>
	<br/><p/>
	<a href="global_tunables.html">*&nbsp;Global&nbsp;Tunables&nbsp;</a>
	<p/><br/><p/>
	<a href="index.html">*&nbsp;Layer Index</a>
	<br/><p/>
	<a href="interfaces.html">*&nbsp;Interface&nbsp;Index</a>
	<br/><p/>
	<a href="templates.html">*&nbsp;Template&nbsp;Index</a>
</div>

<div id="Content">
<h3>Global booleans:</h3>


<div id="interface">
<div id="codeblock">secure_mode</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p>
</p><p>
Enabling secure mode disallows programs, such as
newrole, from transitioning to administrative
user domains.
</p><p>
</p>

</div></div>

<div id="interface">
<div id="codeblock">secure_mode_insmod</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p>
</p><p>
Disable transitions to insmod.
</p><p>
</p>

</div></div>

<div id="interface">
<div id="codeblock">secure_mode_policyload</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p>
</p><p>
boolean to determine whether the system permits loading policy, setting
enforcing mode, and changing boolean values.  Set this to true and you
have to reboot to set it back
</p><p>
</p>

</div></div>


</div>
</body>
</html>