File manager - Edit - /home/veronikagstoette/public_html/selinux.tar
Back
config 0000644 00000001043 15246230623 0005735 0 ustar 00 # This file controls the state of SELinux on the system. # SELINUX= can take one of these three values: # enforcing - SELinux security policy is enforced. # permissive - SELinux prints warnings instead of enforcing. # disabled - No SELinux policy is loaded. SELINUX=disabled # SELINUXTYPE= can take one of these three values: # targeted - Targeted processes are protected, # minimum - Modification of targeted policy. Only selected processes are protected. # mls - Multi Level Security protection. SELINUXTYPE=targeted semanage.conf 0000644 00000005127 15246230623 0007203 0 ustar 00 # Authors: Jason Tang <jtang@tresys.com> # # Copyright (C) 2004-2005 Tresys Technology, LLC # # This library is free software; you can redistribute it and/or # modify it under the terms of the GNU Lesser General Public # License as published by the Free Software Foundation; either # version 2.1 of the License, or (at your option) any later version. # # This library is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU # Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with this library; if not, write to the Free Software # Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA # # Specify how libsemanage will interact with a SELinux policy manager. # The four options are: # # "source" - libsemanage manipulates a source SELinux policy # "direct" - libsemanage will write directly to a module store. # /foo/bar - Write by way of a policy management server, whose # named socket is at /foo/bar. The path must begin # with a '/'. # foo.com:4242 - Establish a TCP connection to a remote policy # management server at foo.com. If there is a colon # then the remainder is interpreted as a port number; # otherwise default to port 4242. module-store = direct # When generating the final linked and expanded policy, by default # semanage will set the policy version to POLICYDB_VERSION_MAX, as # given in <sepol/policydb.h>. Change this setting if a different # version is necessary. #policy-version = 19 # expand-check check neverallow rules when executing all semanage # commands. There might be a penalty in execution time if this # option is enabled. expand-check=0 # usepasswd check tells semanage to scan all pass word records for home directories # and setup the labeling correctly. If this is turned off, SELinux will label only /home # and home directories of users with SELinux login mappings defined, see # semanage login -l for the list of such users. # If you want to use a different home directory, you will need to use semanage fcontext command. # For example, if you had home dirs in /althome directory you would have to execute # semanage fcontext -a -e /home /althome usepasswd=False bzip-small=true bzip-blocksize=5 ignoredirs=/root;/bin;/boot;/dev;/etc;/lib;/lib64;/proc;/run;/sbin;/sys;/tmp;/usr;/var [sefcontext_compile] path = /usr/sbin/sefcontext_compile args = -r $@ [end] targeted/setrans.conf 0000644 00000001137 15246230623 0010676 0 ustar 00 # # Multi-Category Security translation table for SELinux # # Uncomment the following to disable translation libary # disable=1 # # Objects can be categorized with 0-1023 categories defined by the admin. # Objects can be in more than one category at a time. # Categories are stored in the system as c0-c1023. Users can use this # table to translate the categories into a more meaningful output. # Examples: # s0:c0=CompanyConfidential # s0:c1=PatientRecord # s0:c2=Unclassified # s0:c3=TopSecret # s0:c1,c3=CompanyConfidentialRedHat s0=SystemLow s0-s0:c0.c1023=SystemLow-SystemHigh s0:c0.c1023=SystemHigh targeted/booleans.subs_dist 0000644 00000004477 15246230623 0012105 0 ustar 00 allow_auditadm_exec_content auditadm_exec_content allow_console_login login_console_enabled allow_cvs_read_shadow cvs_read_shadow allow_daemons_dump_core daemons_dump_core allow_daemons_use_tcp_wrapper daemons_use_tcp_wrapper allow_daemons_use_tty daemons_use_tty allow_domain_fd_use domain_fd_use allow_execheap selinuxuser_execheap allow_execmod selinuxuser_execmod allow_execstack selinuxuser_execstack allow_ftpd_anon_write ftpd_anon_write allow_ftpd_full_access ftpd_full_access allow_ftpd_use_cifs ftpd_use_cifs allow_ftpd_use_nfs ftpd_use_nfs allow_gssd_read_tmp gssd_read_tmp allow_guest_exec_content guest_exec_content allow_httpd_anon_write httpd_anon_write allow_httpd_mod_auth_ntlm_winbind httpd_mod_auth_ntlm_winbind allow_httpd_mod_auth_pam httpd_mod_auth_pam allow_httpd_sys_script_anon_write httpd_sys_script_anon_write allow_kerberos kerberos_enabled allow_mplayer_execstack mplayer_execstack allow_mount_anyfile mount_anyfile allow_nfsd_anon_write nfsd_anon_write allow_polyinstantiation polyinstantiation_enabled allow_postfix_local_write_mail_spool postfix_local_write_mail_spool allow_rsync_anon_write rsync_anon_write allow_saslauthd_read_shadow saslauthd_read_shadow allow_secadm_exec_content secadm_exec_content allow_smbd_anon_write smbd_anon_write allow_ssh_keysign ssh_keysign allow_staff_exec_content staff_exec_content allow_sysadm_exec_content sysadm_exec_content allow_user_exec_content user_exec_content allow_user_mysql_connect selinuxuser_mysql_connect_enabled allow_user_postgresql_connect selinuxuser_postgresql_connect_enabled allow_write_xshm xserver_clients_write_xshm allow_xguest_exec_content xguest_exec_content allow_xserver_execmem xserver_execmem allow_ypbind nis_enabled allow_zebra_write_config zebra_write_config user_direct_dri selinuxuser_direct_dri_enabled user_ping selinuxuser_ping user_share_music selinuxuser_share_music user_tcp_server selinuxuser_tcp_server sepgsql_enable_pitr_implementation postgresql_can_rsync sepgsql_enable_users_ddl postgresql_selinux_users_ddl sepgsql_transmit_client_label postgresql_selinux_transmit_client_label sepgsql_unconfined_dbadm postgresql_selinux_unconfined_dbadm clamd_use_jit antivirus_use_jit amavis_use_jit antivirus_use_jit logwatch_can_sendmail logwatch_can_network_connect_mail puppet_manage_all_files puppetagent_manage_all_files virt_sandbox_use_nfs virt_use_nfs targeted/.policy.sha512 0000644 00000000201 15246230623 0010641 0 ustar 00 eb52538d47da4b07c0733e93ff344e205e23bb41782be1bde94efec39d91143e7468927c7cbaaa70046bcab4eb2313932c7b65067c2682d9156c789a46b2e39e targeted/policy/policy.31 0000644 00042305035 15246230623 0011325 0 ustar 00 ��|� SE Linux @ @ 7 @ cap setfcap setpcap fowner sys_boot sys_tty_config net_raw sys_admin sys_chroot sys_module sys_rawio dac_override ipc_owner kill dac_read_search sys_pacct net_broadcast net_bind_service sys_nice sys_time fsetid mknod setgid setuid lease net_admin audit_write linux_immutable sys_ptrace audit_control ipc_lock sys_resource chown cap2 checkpoint_restore mac_override mac_admin audit_read syslog block_suspend wake_alarm socket map append bind connect create write relabelfrom ioctl name_bind sendto recv_msg send_msg getattr setattr accept getopt read setopt shutdown recvfrom lock relabelto listen x_device get_property list_property set_property add setfocus create freeze getfocus remove write force_cursor destroy bell getattr grab setattr read manage use database drop create relabelfrom getattr setattr relabelto file map append create execute write relabelfrom link unlink ioctl getattr setattr read rename lock relabelto mounton quotaon swapon ipc associate create write unix_read destroy getattr setattr read unix_write� � u bluetooth_socketsocket� @ � <