Run shells with substitute user and group.
false
Determine whether the user application exec domain attribute should be respected for su access. If not enabled, only user domains themselves may use su.
Execute su in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Restricted su domain template.
This template creates a derived domain which is allowed to change the linux user id, to run shells as a different user.
Parameter: | Description: |
---|---|
userdomain_prefix |
The prefix of the user domain (e.g., user is the prefix for user_t). |
user_domain |
The type of the user domain. |
user_role |
The role associated with the user domain. |
The role template for the su module.
Parameter: | Description: |
---|---|
role_prefix |
The prefix of the user role (e.g., user is the prefix for user_r). |
user_domain |
User domain for the role. |
user_exec_domain |
User exec domain for execute and transition access. |
role |
Role allowed access |