Blob Blame History Raw
<html>
<head>
<title>
 Security Enhanced Linux Reference Policy
 </title>
<style type="text/css" media="all">@import "style.css";</style>
</head>
<body>
<div id="Header">Security Enhanced Linux Reference Policy</div>
<div id='Menu'>
	
		<a href="admin.html">+&nbsp;
		admin</a></br/>
		<div id='subitem'>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_consoletype.html'>
			consoletype</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_dmesg.html'>
			dmesg</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_logrotate.html'>
			logrotate</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_netutils.html'>
			netutils</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_rpm.html'>
			rpm</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='admin_usermanage.html'>
			usermanage</a><br/>
		
		</div>
	
		<a href="apps.html">+&nbsp;
		apps</a></br/>
		<div id='subitem'>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='apps_gpg.html'>
			gpg</a><br/>
		
		</div>
	
		<a href="kernel.html">+&nbsp;
		kernel</a></br/>
		<div id='subitem'>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_bootloader.html'>
			bootloader</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_corenetwork.html'>
			corenetwork</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_devices.html'>
			devices</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_filesystem.html'>
			filesystem</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_kernel.html'>
			kernel</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_selinux.html'>
			selinux</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_storage.html'>
			storage</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='kernel_terminal.html'>
			terminal</a><br/>
		
		</div>
	
		<a href="services.html">+&nbsp;
		services</a></br/>
		<div id='subitem'>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_cron.html'>
			cron</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_inetd.html'>
			inetd</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_kerberos.html'>
			kerberos</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_mta.html'>
			mta</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_nis.html'>
			nis</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_nscd.html'>
			nscd</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_remotelogin.html'>
			remotelogin</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_sendmail.html'>
			sendmail</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='services_ssh.html'>
			ssh</a><br/>
		
		</div>
	
		<a href="system.html">+&nbsp;
		system</a></br/>
		<div id='subitem'>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_authlogin.html'>
			authlogin</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_clock.html'>
			clock</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_corecommands.html'>
			corecommands</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_domain.html'>
			domain</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_files.html'>
			files</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_fstools.html'>
			fstools</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_getty.html'>
			getty</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_hostname.html'>
			hostname</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_hotplug.html'>
			hotplug</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_init.html'>
			init</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_ipsec.html'>
			ipsec</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_iptables.html'>
			iptables</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_libraries.html'>
			libraries</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_locallogin.html'>
			locallogin</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_logging.html'>
			logging</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_lvm.html'>
			lvm</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_miscfiles.html'>
			miscfiles</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_modutils.html'>
			modutils</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_mount.html'>
			mount</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_pcmcia.html'>
			pcmcia</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_raid.html'>
			raid</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_selinuxutil.html'>
			selinuxutil</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_sysnetwork.html'>
			sysnetwork</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_udev.html'>
			udev</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_unconfined.html'>
			unconfined</a><br/>
		
			&nbsp;&nbsp;&nbsp;-&nbsp;<a href='system_userdomain.html'>
			userdomain</a><br/>
		
		</div>
	
	<br/><p/>
	<a href="global_booleans.html">*&nbsp;Global&nbsp;Booleans&nbsp;</a>
	<br/><p/>
	<a href="global_tunables.html">*&nbsp;Global&nbsp;Tunables&nbsp;</a>
	<p/><br/><p/>
	<a href="index.html">*&nbsp;Layer Index</a>
	<br/><p/>
	<a href="interfaces.html">*&nbsp;Interface&nbsp;Index</a>
	<br/><p/>
	<a href="templates.html">*&nbsp;Template&nbsp;Index</a>
</div>

<div id="Content">
<h3>Global tunables:</h3>


<div id="interface">
<div id="codeblock">allow_execmem</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow execution of anonymous mappings, e.g. executable stack.
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">allow_execmod</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Support Share libraries with text relocations
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">allow_gpg_execstack</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow gpg executable stack
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">allow_kerberos</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow system to run with kerberos
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">allow_ypbind</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow system to run with NIS
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">cron_can_relabel</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow system cron jobs to relabel filesystem
for restoring file contexts.
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">fcron_crond</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Enable extra rules in the cron domain
to support fcron.
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">read_default_t</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow reading of default_t files.
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">run_ssh_inetd</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow ssh to run from inetd instead of as a daemon.
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">ssh_sysadm_login</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow ssh logins as sysadm_r:sysadm_t
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">staff_read_sysadm_file</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow staff_r users to search the sysadm home 
dir and read files (such as ~/.bashrc)
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">use_dns</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow the use of DNS for name resolution.
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">use_nfs_home_dirs</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Support NFS home directories
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">use_samba_home_dirs</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Support SAMBA home directories
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">user_direct_mouse</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow regular users direct mouse access 
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">user_dmesg</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow users to read system messages.
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">user_net_control</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow users to control network interfaces
(also needs USERCTL=true)
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">user_ping</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Control users use of ping and traceroute
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">user_rw_noexattrfile</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow user to r/w noextattrfile (FAT, CDROM, FLOPPY)
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">user_rw_usb</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow users to rw usb devices
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">user_tcp_server</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow users to run TCP servers (bind to ports and accept connection from
the same domain and outside users)  disabling this forces FTP passive mode
and may change other protocols.
</p></p>

</div></div>

<div id="interface">
<div id="codeblock">user_ttyfile_stat</div>
<div id="description">
<h5>Default value</h5>
<p>false</p>

<h5>Description</h5>
<p><p>
Allow w to display everyone
</p></p>

</div></div>


</div>
</body>
</html>