Common policy for authentication and user login.
false
Allow users to resolve user passwd entries directly from ldap rather then using a sssd server
false
Allow users to login using a radius server
false
Allow users to login using a yubikey OTP server or challenge response mode
Append to the login failure log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Append only to the last logins log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Append to login records (wtmp).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Pass shadow assertion for reading.
Pass shadow assertion for reading. This should only be used with auth_tunable_read_shadow(), and only exists because typeattribute does not work in conditionals.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create authentication cache
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage create logins log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create pam var console pid directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete pam_console data.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete pam PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Run unix_chkpwd to check a password.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Run unix_chkpwd to check a password. Stripped down version to be called within boolean
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute a login_program in the target domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
target_domain |
The type of the login_program process. |
Execute pam timestamp programs in the pam timestamp domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute pam_console with a domain transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute pam timestamp programs in the pam timestamp domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute a domain transition to run unix_update.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute utempter programs in the utempter domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Do not audit attemps to execute utempter executable.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of the passwd passwords file.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of the shadow passwords file.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read login records files (/var/log/wtmp).
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attemps to read PAM PID files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read the passwd password file (/etc/passwd).
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit reading the passwd passwords file
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Do not audit attempts to read the shadow password file (/etc/shadow).
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to write to login records files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Automatic transition from etc to shadow.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute chkpwd in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute a login_program in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute the pam program.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type usable as a login file.
Make the specified type usable as a login file, This type has restricted modification capabilities when used with other interfaces that permit files_type access. The default type has properties similar to that of the shadow file. This will also make the type usable as a security file, making calls to files_security_file() redundant.
Parameter: | Description: |
---|---|
type |
Type to be used as a login file. |
Create auth directory in the /root directory with an correct label.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create auth directory in the config home directory with a correct label.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create auth directory in the user home directory with an correct label.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to authlogin named content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of the passwd passwords file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of the shadow passwords file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List the contents of the pam_console data directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create a login records in the log directory using a type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Use the login program as an entry point program.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage the keyrings of all login programs
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified domain used for a login program.
Parameter: | Description: |
---|---|
domain |
Domain type used for a login program domain. |
Send a SIGCHLD signal to login programs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage all files on the filesystem, except login files passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Manage all files on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Manage authentication cache
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage the login failure log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the authorization data in the user home directory
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete login records files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete pam_console data files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage pam PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete the passwd password file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete the shadow password file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage var auth files. Used by various other applications and pam applets etc.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mmap the passwd passwords file (/etc/passwd)
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mmap the shadow passwords file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create specified objects in pid directories with the pam var console pid file type using a file type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
object_class |
Class of the object being created. |
name |
The name of the object being created. |
Execute a login_program in the target domain, with a range transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
target_domain |
The type of the login_program process. |
range |
Range of the login program. |
Read all directories on the filesystem, except login files and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read all directories on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read all files on the filesystem, except login files and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read all files on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read all symbolic links on the filesystem, except login files and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read all symbolic links on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read authentication cache
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the authorization data in the user home directory
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the last logins log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read login records files (/var/log/wtmp).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read pam_console data files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read PAM PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the passwd passwords file (/etc/passwd) Allow to use sss nsswitch module for passwd and group. Allow to use systemd nsswitch module for passwd and group which is used for dynamic users.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the passwd passwords file (/etc/passwd) only
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the shadow passwords file (/etc/shadow)
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read var auth files. Used by various other applications and pam applets etc.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read access to the authlogin module.
Read access to the authlogin module.
Currently, this only allows assertions for the shadow passwords file (/etc/shadow) to be passed. No access is granted yet.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel all files on the filesystem, except login files and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Relabel all files on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Relabel the login failure log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel login record files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel pam_console data directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel from and to the shadow password file type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel all var auth files. Used by various other applications and pam applets etc.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel to the password file type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel to the shadow password file type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Role access for password authentication.
Parameter: | Description: |
---|---|
role |
Role allowed access. |
domain |
Domain allowed access. |
Execute chkpwd programs in the chkpwd domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
The role to allow the chkpwd domain. |
Execute pam_timestamp programs in the PAM timestamp domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
The role to allow the PAM domain. |
Execute pam_console in the pam timestamp domain
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
The role to allow transitioning into the pam_console_t domain. |
Execute pam_timestamp programs in the PAM timestamp domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
The role to allow the PAM domain. |
Execute updpwd programs in the updpwd domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
The role to allow the updpwd domain. |
Execute utempter programs in the utempter domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
The role to allow the utempter domain. |
Read and write all files on the filesystem, except login files and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read and write all files on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read/Write authentication cache
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write the login failure log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write to the last logins log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write login records.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write the shadow password file (/etc/shadow).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write var auth files. Used by various other applications and pam applets etc.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search authentication cache
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search the contents of the pam_console data directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Set the attributes of login record files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send generic signals to chkpwd processes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send generic signals to pam processes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the shadow password file.
Read the shadow password file. This should only be used in a conditional; it does not pass the reading shadow assertion.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unconfined access to the authlogin module.
Unconfined access to the authlogin module.
Currently, this only allows assertions for the shadow passwords file (/etc/shadow) to be passed. No access is granted yet.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Use nsswitch to look up user, password, group, or host information.
Allow the specified domain to look up user, password, group, or host information using the name service. The most common use of this interface is for services that do host name resolution (usually DNS resolution).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Use PAM for authentication.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Automatic transition from cache_t to cache.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch the passwd passwords file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write to login records (wtmp).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write access to the authlogin module.
Write access to the authlogin module.
Currently, this only allows assertions for the shadow passwords file (/etc/shadow) to be passed. No access is granted yet.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read authlogin state files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write a authlogin unnamed pipe.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |