Global tunables:

allow_execheap
Default value

false

Description

Allow unconfined executables to make their heap memory executable. Doing this is a really bad idea. Probably indicates a badly coded executable, but could indicate an attack. This executable should be reported in bugzilla

allow_execmem
Default value

false

Description

Allow unconfined executables to map a memory region as both executable and writable, this is dangerous and the executable should be reported in bugzilla")

allow_execmod
Default value

false

Description

Allow all unconfined executables to use libraries requiring text relocation that are not labeled textrel_shlib_t")

allow_execstack
Default value

false

Description

Allow unconfined executables to make their stack executable. This should never, ever be necessary. Probably indicates a badly coded executable, but could indicate an attack. This executable should be reported in bugzilla")

allow_polyinstantiation
Default value

false

Description

Enable polyinstantiated directory support.

allow_raw_memory_access
Default value

false

Description

Allow raw memory device (/dev/mem, /dev/kmem, /dev/mergemem, dev/oldmem, /dev/port) access for confined executables. This is extremely dangerous as it can bypass the SELinux protections, and should only be used by trusted domains.

allow_ypbind
Default value

false

Description

Allow system to run with NIS

console_login
Default value

true

Description

Allow logging in and using the system from /dev/console.

global_ssp
Default value

false

Description

Enable reading of urandom for all domains.

This should be enabled when all programs are compiled with ProPolice/SSP stack smashing protection. All domains will be allowed to read from /dev/urandom.

mail_read_content
Default value

false

Description

Allow email client to various content. nfs, samba, removable devices, and user temp files

nfs_export_all_ro
Default value

false

Description

Allow any files/directories to be exported read/only via NFS.

nfs_export_all_rw
Default value

false

Description

Allow any files/directories to be exported read/write via NFS.

use_nfs_home_dirs
Default value

false

Description

Support NFS home directories

use_samba_home_dirs
Default value

false

Description

Support SAMBA home directories

user_tcp_server
Default value

false

Description

Allow users to run TCP servers (bind to ports and accept connection from the same domain and outside users) disabling this forces FTP passive mode and may change other protocols.

user_udp_server
Default value

false

Description

Allow users to run UDP servers (bind to ports and accept connection from the same domain and outside users)