Global booleans:

secure_mode
Default value

false

Description

disallow programs, such as newrole, from transitioning to administrative user domains.

secure_mode_insmod
Default value

false

Description

disallow programs and users from transitioning to insmod domain.

secure_mode_policyload
Default value

false

Description

prevent all confined domains from loading policy, setting enforcing mode, and changing boolean values. Set this to true and you have to reboot to set it back