Common policy for authentication and user login.
Append to the login failure log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Append only to the last logins log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Append to login records (wtmp).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Pass shadow assertion for reading.
Pass shadow assertion for reading. This should only be used with auth_tunable_read_shadow(), and only exists because typeattribute does not work in conditionals.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete pam_console data.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete pam PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Run unix_chkpwd to check a password.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Run unix_chkpwd to check a password. Stripped down version to be called within boolean
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a login_program in the target domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
target_domain |
The type of the login_program process. |
Execute pam programs in the pam domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute pam_console with a domain transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a domain transition to run unix_update.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute utempter programs in the utempter domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Do not audit attemps to execute utempter executable.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of the shadow passwords file.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attemps to read PAM PID files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read the shadow password file (/etc/shadow).
Parameter: | Description: |
---|---|
domain |
The type of the domain to not audit. |
Do not audit attempts to write to login records files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Automatic transition from etc to shadow.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute the pam program.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Automatic transition from cache_t to cache.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of the shadow passwords file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List the contents of the pam_console data directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create a login records in the log directory using a type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Use the login program as an entry point program.
Parameter: | Description: |
---|---|
domain |
The type of process using the login program as entry point. |
Make the specified domain used for a login program.
Parameter: | Description: |
---|---|
domain |
Domain type used for a login program domain. |
Manage all files on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
The type of the domain perfoming this action. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Manage authentication cache
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete login records files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete pam_console data files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage pam PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete the shadow password file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage var auth files. Used by various other applications and pam applets etc.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a login_program in the target domain, with a range transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
target_domain |
The type of the login_program process. |
range |
Range of the login program. |
Read all directories on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
The type of the domain perfoming this action. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read all files on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
The type of the domain perfoming this action. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read all symbolic links on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
The type of the domain perfoming this action. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read authentication cache
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the last logins log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read login records files (/var/log/wtmp).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read pam_console data files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read PAM PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the shadow passwords file (/etc/shadow)
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel all files on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
The type of the domain perfoming this action. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Relabel from and to the shadow password file type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel to the shadow password file type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Role access for password authentication.
Parameter: | Description: |
---|---|
role |
Role allowed access. |
domain |
Domain allowed access. |
Execute chkpwd programs in the chkpwd domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
The role to allow the chkpwd domain. |
Execute pam programs in the PAM domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
The role to allow the PAM domain. |
Execute updpwd programs in the updpwd domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
The role to allow the updpwd domain. |
Execute utempter programs in the utempter domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
The role to allow the utempter domain. |
rw all files on the filesystem, except the shadow passwords and listed exceptions.
Parameter: | Description: |
---|---|
domain |
The type of the domain perfoming this action. |
exception_types |
The types to be excluded. Each type or attribute must be negated by the caller. |
Read/Write authentication cache
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write the login failure log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write to the last logins log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write login records.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write the shadow password file (/etc/shadow).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search authentication cache
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search the contents of the pam_console data directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Set the attributes of login record files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send signal to pam process
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the shadow password file.
Read the shadow password file. This should only be used in a conditional; it does not pass the reading shadow assertion.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unconfined access to the authlogin module.
Unconfined access to the authlogin module.
Currently, this only allows assertions for the shadow passwords file (/etc/shadow) to be passed. No access is granted yet.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Use nsswitch to look up uid-username mappings.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write to login records (wtmp).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |