Various web servers.
false
Determine whether httpd can modify public files used for public file transfer services. Directories/Files must be labeled public_content_rw_t.
false
Determine whether httpd can use mod_auth_pam.
false
Determine whether the script domain can modify public files used for public file transfer services. Directories/Files must be labeled public_content_rw_t.
false
Determine whether the script domain can modify public files used for public file transfer services. Directories/Files must be labeled public_content_rw_t.
false
Determine whether the script domain can modify public files used for public file transfer services. Directories/Files must be labeled public_content_rw_t.
false
Determine whether httpd can use built in scripting.
false
Determine whether httpd can check spam.
false
Determine whether httpd scripts and modules can connect to the network using TCP.
false
Determine whether httpd scripts and modules can connect to cobbler over the network.
false
Determine whether scripts and modules can connect to databases over the network.
false
Determine whether httpd can connect to ldap over the network.
false
Determine whether httpd can connect to memcache server over the network.
false
Determine whether httpd daemon can connect to zabbix over the network.
false
Determine whether httpd can act as a relay.
false
Determine whether httpd can send mail.
false
Determine whether httpd can communicate with avahi service via dbus.
false
Determine whether httpd can use support.
false
Determine whether httpd can act as a FTP server by listening on the ftp port.
false
Determine whether httpd can traverse user home directories.
false
Determine whether httpd scripts and modules can use execmem and execstack.
false
Determine whether httpd gpg can modify public files used for public file transfer services. Directories/Files must be labeled public_content_rw_t.
false
Determine whether httpd can connect to port 80 for graceful shutdown.
false
Determine whether httpd can manage IPA content files.
false
Determine whether httpd can use mod_auth_ntlm_winbind.
false
Determine whether httpd can read generic user home content files.
false
Determine whether httpd can change its resource limits.
false
Determine whether httpd can run SSI executables in the same domain as system CGI scripts.
false
Determine whether httpd can execute its temporary content.
false
Determine whether httpd can communicate with the terminal. Needed for entering the passphrase for certificates at the terminal.
false
Determine whether httpd can have full access to its content types.
false
Determine whether httpd can use cifs file systems.
false
Determine whether httpd can use fuse file systems.
false
Determine whether httpd can use gpg.
false
Determine whether httpd can use nfs file systems.
All of the rules required to administrate an apache environment.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
Role allowed access. |
Append to all appendable web content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Append httpd log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Append httpd squirrelmail data files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute CGI in the specified domain.
This is an interface to support third party modules and its use is not allowed in upstream reference policy.
Parameter: | Description: |
---|---|
domain |
Domain run the cgi script in. |
entrypoint |
Type of the executable to enter the cgi domain. |
Delete httpd cache directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete httpd cache files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete httpd_var_lib_t files
Parameter: | Description: |
---|---|
domain |
Domain that can delete the files |
delete httpd squirrelmail spool files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute httpd with a domain transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute all user scripts in the user script domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute the Apache helper program with a domain transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a domain transition to run httpd_rotatelogs.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute all httpd scripts in the system script domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Do not audit attempts to append httpd log files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write httpd unnamed pipes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write httpd unix domain stream sockets.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write httpd system script unix domain stream sockets.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write httpd TCP sockets.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to search httpd module directories.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to write httpd tmp files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Execute httpd
Parameter: | Description: |
---|---|
domain |
Domain allowed to execute it. |
Execute httpd module files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute httpd server in the httpd domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
List all apache content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List httpd cache directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List httpd module directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List httpd system content directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete all httpd content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage all read/write content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete all user httpd content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete httpd configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete httpd log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete httpd system content files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete httpd system rw content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read all web content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read all appendable content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read all read/write content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read httpd configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read httpd log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read httpd module files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read httpd squirrelmail data files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read httpd system content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read httpd tmp files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read user httpd content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read user httpd script executable files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Reload the httpd service (systemd).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute all user scripts in the user script domain. Add user script domains to the specified role.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
Role allowed access. |
Execute the Apache helper program with a domain transition, and allow the specified role the Apache helper domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
Role allowed access. |
Read and write httpd cache files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
rw httpd_runtime_t files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write httpd unix domain stream sockets.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search all apache content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search httpd configuration directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search httpd system content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search system script state directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search httpd system CGI directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Set attributes httpd cache directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send child terminated signals to httpd.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send generic signals to httpd.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send null signals to httpd.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Inherit and use file descriptors from httpd.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write apache log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create a set of derived types for httpd web content.
Parameter: | Description: |
---|---|
prefix |
The prefix to be used for deriving type names. |
Role access for apache.
Parameter: | Description: |
---|---|
role_prefix |
The prefix of the user role (e.g., user is the prefix for user_r). |
user_domain |
User domain for the role. |
user_exec_domain |
User exec domain for execute and transition access. |
role |
Role allowed access |