Common e-mail transfer agent policy.
Admin Role access for mta.
Parameter: | Description: |
---|---|
role |
Role allowed access. |
domain |
User domain for the role. |
Make the specified type a MTA executable file.
Parameter: | Description: |
---|---|
type |
Type to be used as a mail client. |
Create, read, and write mail spool files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete mail spool files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Do not audit attempts to get attributes of mail spool files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read mail spool symlinks.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write TCP sockets of mail delivery domains.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write mail queue content.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Create specified object in generic etc directories with the mail address alias type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
object |
The object class of the object being created. |
name |
The name of the object being created. |
Get attributes of mail spool content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create specified objects in user home directories with the generic mail home type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
object_class |
Class of the object being created. |
name |
The name of the object being created. |
Create specified objects in user home directories with the generic mail home rw type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
object_class |
Class of the object being created. |
name |
The name of the object being created. |
Send kill signals to system mail.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List mail queue directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow listing the mail spool.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Make the specified domain usable for a mail server.
Parameter: | Description: |
---|---|
type |
Type to be used as a mail server domain. |
entry_point |
Type of the program to be used as an entry point to this domain. |
Make a type a mailserver type used for delivering mail to local users.
Parameter: | Description: |
---|---|
domain |
Mail server domain type used for delivering mail. |
Make a type a mailserver type used for sending mail.
Parameter: | Description: |
---|---|
domain |
Mail server domain type used for sending mail. |
Make a type a mailserver type used for sending mail on behalf of local users to the local mail spool.
Parameter: | Description: |
---|---|
domain |
Mail server domain type used for sending local mail. |
Create, read, write, and delete mail address alias content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete mta mail home files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete mta mail home rw content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete mail queue content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete mail spool content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read mail address alias files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create specified objects in the mail queue spool directory with a private type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private type |
The type of the object to be created. |
object |
The object class of the object being created. |
name |
The name of the object being created. |
Read mail address alias files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read mail server configuration content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read mta mail home files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read mail queue files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read sendmail binary.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read mail spool files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow reading mail spool symlinks.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Read and write mail alias files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
read and write fifo files inherited from delivery domains
Parameter: | Description: |
---|---|
domain |
Domain to use fifo files |
Read and write mail spool files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write unix domain stream sockets of all base mail domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search mail queue directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send mail from the system.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute send mail in a specified domain.
Execute send mail in a specified domain.
No interprocess communication (signals, pipes, etc.) is provided by this interface since the domains are not owned by this module.
Parameter: | Description: |
---|---|
source_domain |
Domain allowed to transition. |
target_domain |
Domain to transition to. |
Make sendmail usable as an entry point for the domain.
Parameter: | Description: |
---|---|
domain |
Domain to be entered. |
Execute sendmail in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Modified mailserver interface for sendmail daemon use.
A modified MTA mail server interface for the sendmail program. It's design does not fit well with policy, and using the regular interface causes a type_transition conflict if direct running of init scripts is enabled.
This interface should most likely only be used by the sendmail policy.
Parameter: | Description: |
---|---|
domain |
The type to be used for the mail server. |
Send signals to system mail.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create specified objects in specified directories with a type transition to the mail address alias type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
file_type |
Directory to transition on. |
object |
The object class of the object being created. |
name |
The name of the object being created. |
Create specified objects in the mail spool directory with a private type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private type |
The type of the object to be created. |
object |
The object class of the object being created. |
name |
The name of the object being created. |
MTA stub interface. No access allowed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type by a system MTA.
Parameter: | Description: |
---|---|
type |
Type to be used as a mail client. |
Allow system_mail_t to run in a role
Parameter: | Description: |
---|---|
domain |
Role allowed access. |
Inherit FDs from mailserver_domain domains
Parameter: | Description: |
---|---|
type |
Type for a list server or delivery agent that inherits fds |
User Role access for mta.
Parameter: | Description: |
---|---|
role |
Role allowed access. |
domain |
User domain for the role. |
Watch mail spool content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write mail server configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
The template to define a mail domain.
Parameter: | Description: |
---|---|
domain_prefix |
Domain prefix to be used. |
Role access for mta.
Parameter: | Description: |
---|---|
role_prefix |
The prefix of the user role (e.g., user is the prefix for user_r). |
user_domain |
User domain for the role. |
user_exec_domain |
User exec domain for execute and transition access. |
role |
Role allowed access |