Policy for kernel threads, proc filesystem, and unlabeled processes and objects.
Module: | Description: |
corecommands | Core policy for shells, and generic programs in /bin, /sbin, /usr/bin, and /usr/sbin. |
corenetwork | Policy controlling access to network objects |
devices | Device nodes and interfaces for many basic system devices. |
domain | Core policy for domains. |
files | Basic filesystem types and interfaces. |
filesystem | Policy for filesystems. |
kernel | Policy for kernel threads, proc filesystem, and unlabeled processes and objects. |
mcs | Multicategory security policy |
mls | Multilevel security policy |
selinux | Policy for kernel security interface, in particular, selinuxfs. |
storage | Policy controlling access to storage devices |
terminal | Policy for terminals. |
ubac | User-based access control policy |
unlabelednet | Policy for allowing confined domains to use unlabeled_t packets |
Policy modules for user roles.
Module: | Description: |
auditadm | Audit administrator role |
logadm | Log administrator role |
secadm | Security administrator role |
staff | Administrator's unprivileged user |
sysadm | General system administration role |
sysadm_secadm | No Interfaces |
unconfineduser | Unconfiend user role |
unprivuser | Generic unprivileged user |
Policy modules for administrative functions, such as package management.
Module: | Description: |
bootloader | Policy for the kernel modules, kernel image, and bootloader. |
consoletype | Determine of the console connected to the controlling terminal. |
dmesg | Policy for dmesg. |
netutils | Network analysis utilities |
su | Run shells with substitute user and group |
sudo | Execute a command with a substitute user |
usermanage | Policy for managing user accounts. |
Policy modules for applications
Module: | Description: |
seunshare | Filesystem namespacing/polyinstantiation application. |
Policy modules for system functions from init to multi-user login.
Module: | Description: |
application | Policy for user executable applications. |
authlogin | Common policy for authentication and user login. |
clock | Policy for reading and setting the hardware clock. |
fstools | Tools for filesystem management, such as mkfs and fsck. |
getty | Policy for getty. |
hostname | Policy for changing the system host name. |
hotplug | Policy for hotplug system, for supporting the connection and disconnection of devices at runtime. |
init | System initialization programs (init and init scripts). |
ipsec | TCP/IP encryption |
iptables | Policy for iptables. |
libraries | Policy for system libraries. |
locallogin | Policy for local logins. |
logging | Policy for the kernel message logger and system logging daemon. |
lvm | Policy for logical volume management programs. |
miscfiles | Miscelaneous files. |
modutils | Policy for kernel module utilities |
mount | Policy for mount. |
netlabel | NetLabel/CIPSO labeled networking management |
selinuxutil | Policy for SELinux policy and userland applications. |
setrans | SELinux MLS/MCS label translation service. |
sysnetwork | Policy for network configuration: ifconfig and dhcp client. |
systemd | SELinux policy for systemd components |
udev | Policy for udev. |
unconfined | The unconfined domain. |
userdomain | Policy for user domains |
Policy modules for system services, like cron, and network services, like sshd.
Module: | Description: |
postgresql | PostgreSQL relational database |
ssh | Secure shell client and server policy. |
xserver | X Windows Server |
Contributed Reference Policy modules.
Module: | Description: |
abrt | ABRT - automated bug-reporting tool |
accountsd | AccountsService and daemon for manipulating user account information via D-Bus |
acct | Berkeley process accounting |
ada | GNAT Ada95 compiler |
afs | Andrew Filesystem server |
aiccu | Automatic IPv6 Connectivity Client Utility. |
aide | Aide filesystem integrity checker |
aisexec | Aisexec Cluster Engine |
ajaxterm | policy for ajaxterm |
alsa | Ainit ALSA configuration tool. |
amanda | Advanced Maryland Automatic Network Disk Archiver. |
amavis | Daemon that interfaces mail transfer agents and content checkers, such as virus scanners. |
amtu | Abstract Machine Test Utility. |
anaconda | Anaconda installer. |
antivirus | SELinux policy for antivirus programs. |
apache | Apache web server |
apcupsd | APC UPS monitoring daemon |
apm | Advanced power management daemon |
apt | APT advanced package tool. |
arpwatch | Ethernet activity monitor. |
asterisk | Asterisk IP telephony server |
authbind | Tool for non-root processes to bind to reserved ports |
authconfig | policy for authconfig |
automount | Filesystem automounter service. |
avahi | mDNS/DNS-SD daemon implementing Apple ZeroConf architecture |
awstats | AWStats is a free powerful and featureful tool that generates advanced web, streaming, ftp or mail server statistics, graphically. |
backup | System backup scripts |
bacula | bacula backup program |
bcfg2 | bcfg2-server daemon which serves configurations to clients based on the data in its repository |
bind | Berkeley internet name domain DNS server. |
bitlbee | Bitlbee service |
blueman | Blueman is a tool to manage Bluetooth devices |
bluetooth | Bluetooth tools and system services. |
boinc | policy for boinc |
brctl | Utilities for configuring the linux ethernet bridge |
bugzilla | Bugzilla server |
cachefilesd | policy for cachefilesd |
calamaris | Squid log analysis |
callweaver | Open source PBX project. |
canna | Canna - kana-kanji conversion server |
ccs | Cluster Configuration System |
cdrecord | Policy for cdrecord |
certmaster | Certmaster SSL certificate distribution service |
certmonger | Certificate status monitor and PKI enrollment client |
certwatch | Digital Certificate Tracking |
cfengine | policy for cfengine |
cgroup | libcg is a library that abstracts the control group file system in Linux. |
chrome | policy for chrome |
chronyd | Chrony NTP background daemon |
cipe | Encrypted tunnel daemon |
clamav | ClamAV Virus Scanner |
clockspeed | Clockspeed simple network time protocol client |
clogd | clogd - Clustered Mirror Log Server |
cloudform | cloudform policy |
cmirrord | Cluster mirror log daemon |
cobbler | Cobbler installation server. |
collectd | policy for collectd |
colord | GNOME color manager |
comsat | Comsat, a biff server. |
condor | policy for condor |
consolekit | Framework for facilitating multiple user sessions on desktops. |
corosync | Corosync Cluster Engine |
couchdb | policy for couchdb |
courier | Courier IMAP and POP3 email servers |
cpucontrol | Services for loading CPU microcode and CPU frequency scaling. |
cpufreqselector | Command-line CPU frequency settings. |
cron | Periodic execution of scheduled commands. |
ctdbd | policy for ctdbd |
cups | Common UNIX printing system |
cvs | Concurrent versions system |
cyphesis | Cyphesis WorldForge game server |
cyrus | Cyrus is an IMAP service intended to be run on sealed servers |
daemontools | Collection of tools for managing UNIX services |
dante | Dante msproxy and socks4/5 proxy server |
dbadm | Database administrator role |
dbskk | Dictionary server for the SKK Japanese input method system. |
dbus | Desktop messaging bus |
dcc | Distributed checksum clearinghouse spam filtering |
ddclient | Update dynamic IP address at DynDNS.org |
ddcprobe | ddcprobe retrieves monitor and graphics card information |
denyhosts | DenyHosts SSH dictionary attack mitigation |
devicekit | Devicekit modular hardware abstraction layer |
dhcp | Dynamic host configuration protocol (DHCP) server |
dictd | Dictionary daemon |
dirsrv | policy for dirsrv |
dirsrv-admin | Administration Server for Directory Server, dirsrv-admin. |
distcc | Distributed compiler daemon |
djbdns | small and secure DNS daemon |
dkim | DomainKeys Identified Mail milter. |
dmidecode | Decode DMI data for x86/ia64 bioses. |
dnsmasq | dnsmasq DNS forwarder and DHCP server |
dnssec | policy for dnssec_trigger |
dovecot | Dovecot POP and IMAP mail server |
dpkg | Policy for the Debian package manager. |
drbd | policy for drbd |
dspam | policy for dspam |
entropyd | Generate entropy from audio input |
evolution | Evolution email client |
exim | Exim mail transfer agent |
fail2ban | Update firewall filtering to ban IP addresses with too many password failures. |
fcoemon | policy for fcoemon |
fetchmail | Remote-mail retrieval and forwarding utility |
finger | Finger user information service. |
firewalld | policy for firewalld |
firewallgui | policy for firewallgui |
firstboot | Final system configuration run during the first boot after installation of Red Hat/Fedora systems. |
fprintd | DBus fingerprint reader service |
ftp | File transfer protocol service |
games | Games |
gatekeeper | OpenH.323 Voice-Over-IP Gatekeeper |
gift | giFT peer to peer file sharing tool |
git | GIT revision control system. |
gitosis | Tools for managing and hosting git repositories. |
glance | policy for glance |
glusterd | policy for glusterd |
gnome | GNU network object model environment (GNOME) |
gnomeclock | Gnome clock handler for setting the time. |
gpg | Policy for GNU Privacy Guard and related programs. |
gpm | General Purpose Mouse driver |
gpsd | gpsd monitor daemon |
guest | Least privledge terminal user role |
hadoop | Software for reliable, scalable, distributed computing. |
hal | Hardware abstraction layer |
hddtemp | hddtemp hard disk temperature tool running as a daemon. |
howl | Port of Apple Rendezvous multicast DNS |
i18n_input | IIIMF htt server |
icecast | ShoutCast compatible streaming media server |
ifplugd | Bring up/down ethernet interfaces based on cable detection. |
imaze | iMaze game server |
inetd | Internet services daemon. |
inn | Internet News NNTP server |
irc | IRC client policy |
ircd | IRC server |
irqbalance | IRQ balancing daemon |
iscsi | Establish connections to iSCSI devices |
isnsd | policy for isnsd |
jabber | Jabber instant messaging server |
java | Java virtual machine |
jetty | policy for jetty |
jockey | policy for jockey |
kde | Policy for KDE components |
kdump | Kernel crash dumping mechanism |
kdumpgui | system-config-kdump GUI |
kerberos | MIT Kerberos admin and KDC |
kerneloops | Service for reporting kernel oopses to kerneloops.org |
keyboardd | policy for system-setup-keyboard daemon |
keystone | policy for keystone |
kismet | Kismet is an 802.11 layer2 wireless network detector, sniffer, and intrusion detection system. |
ksmtuned | Kernel Samepage Merging (KSM) Tuning Daemon |
ktalk | KDE Talk daemon |
kudzu | Hardware detection and configuration tools |
l2tpd | Layer 2 Tunneling Protocol daemons. |
ldap | OpenLDAP directory server |
likewise | Likewise Active Directory support for UNIX. |
lircd | Linux infared remote control daemon |
livecd | Livecd tool for building alternate livecd for different os and policy versions. |
lldpad | policy for lldpad |
loadkeys | Load keyboard mappings. |
lockdev | device locking policy for lockdev |
logrotate | Rotate and archive system logs |
logwatch | System log analyzer and reporter |
lpd | Line printer daemon |
mailman | Mailman is for managing electronic mail discussion and e-newsletter lists |
mailscanner | E-mail security and anti-spam package for e-mail gateway systems. |
man2html | policy for httpd_man2html_script |
mandb | policy for mandb |
mcelog | policy for mcelog |
mcollective | policy for mcollective |
mediawiki | Mediawiki policy |
memcached | high-performance memory object caching system |
milter | Milter mail filters |
mock | policy for mock |
modemmanager | Provides a DBus interface to communicate with mobile broadband (GSM, CDMA, UMTS, ...) cards. |
mojomojo | MojoMojo Wiki |
mono | Run .NET server and client applications on Linux. |
monop | Monopoly daemon |
mozilla | Policy for Mozilla and related web browsers |
mpd | Music Player Daemon |
mplayer | Mplayer media player and encoder |
mrtg | Network traffic graphing |
mta | Policy common to all email tranfer agents. |
munin | Munin network-wide load graphing (formerly LRRD) |
mysql | Policy for MySQL |
nagios | Net Saint / NAGIOS - network monitoring server |
namespace | policy for namespace |
ncftool | Netcf network configuration tool (ncftool). |
nessus | Nessus network scanning daemon |
networkmanager | Manager for dynamically switching between networks. |
nis | Policy for NIS (YP) servers and clients |
nova | openstack-nova |
nscd | Name service cache daemon |
nsd | Authoritative only name server |
nslcd | nslcd - local LDAP name service daemon. |
nsplugin | policy for nsplugin |
ntop | Network Top |
ntp | Network time protocol daemon |
numad | policy for numad |
nut | nut - Network UPS Tools |
nx | NX remote desktop |
oav | Open AntiVirus scannerdaemon and signature update |
obex | SELinux policy for obex-data-server |
oddjob | Oddjob provides a mechanism by which unprivileged applications can request that specified privileged operations be performed on their behalf. |
oident | SELinux policy for Oident daemon. |
openca | OpenCA - Open Certificate Authority |
openct | Service for handling smart card readers. |
openhpid | policy for openhpid |
openshift | policy for openshift |
openshift-origin | |
openvpn | full-featured SSL VPN solution |
openvswitch | policy for openvswitch |
pacemaker | policy for pacemaker |
pads | Passive Asset Detection System |
passenger | Ruby on rails deployment for Apache and Nginx servers. |
pcmcia | PCMCIA card management services |
pcscd | PCSC smart card service |
pegasus | The Open Group Pegasus CIM/WBEM Server. |
perdition | Perdition POP and IMAP proxy |
phpfpm | PHP-FPM (FastCGI Process Manager) is an alternative PHP FastCGI implementation with some additional features useful for sites of any size, especially busier sites. |
pingd | Pingd of the Whatsup cluster node up/down detection utility |
piranha | policy for piranha |
pkcsslotd | policy for pkcsslotd |
pki | policy for pki |
plymouthd | Plymouth graphical boot |
podsleuth | Podsleuth is a tool to get information about an Apple (TM) iPod (TM) |
policykit | Policy framework for controlling privileges for system-wide services. |
polipo | Caching web proxy. |
portage | Portage Package Management System. The primary package management and distribution system for Gentoo. |
portmap | RPC port mapping service. |
portreserve | Reserve well-known ports in the RPC port range. |
portslave | Portslave terminal server software |
postfix | Postfix email server |
postfixpolicyd | Postfix policy server |
postgrey | Postfix grey-listing server |
ppp | Point to Point Protocol daemon creates links in ppp networks |
prelink | Prelink ELF shared library mappings. |
prelude | Prelude hybrid intrusion detection system |
privoxy | Privacy enhancing web proxy. |
procmail | Procmail mail delivery agent |
psad | Intrusion Detection and Log Analysis with iptables |
ptchown | helper function for grantpt(3), changes ownship and permissions of pseudotty |
publicfile | publicfile supplies files to the public through HTTP and FTP |
pulseaudio | Pulseaudio network sound server. |
puppet | Puppet client daemon |
pwauth | policy for pwauth |
pxe | Server for the PXE network boot protocol |
pyicqt | PyICQt is an ICQ transport for XMPP server. |
pyzor | Pyzor is a distributed, collaborative spam detection and filtering network. |
qemu | QEMU machine emulator and virtualizer |
qmail | Qmail Mail Server |
qpid | policy for qpidd |
quantum | Quantum is a virtual network service for Openstack |
quota | File system quota management |
rabbitmq | policy for rabbitmq |
radius | RADIUS authentication and accounting server. |
radvd | IPv6 router advertisement daemon |
raid | RAID array management tools |
razor | A distributed, collaborative, spam detection and filtering network. |
rdisc | Network router discovery daemon |
readahead | Readahead, read files into page cache for improved performance |
realmd | dbus system service which manages discovery and enrollment in realms and domains like Active Directory or IPA |
remotelogin | Policy for rshd, rlogind, and telnetd. |
resmgr | Resource management daemon |
rgmanager | rgmanager - Resource Group Manager |
rhcs | RHCS - Red Hat Cluster Suite |
rhev | rhev polic module contains policies for rhev apps |
rhgb | Red Hat Graphical Boot |
rhnsd | policy for rhnsd |
rhsmcertd | Subscription Management Certificate Daemon policy |
ricci | Ricci cluster management agent |
rlogin | Remote login daemon |
rngd | Check and feed random data from hardware device to kernel random device. |
roundup | Roundup Issue Tracking System policy |
rpc | Remote Procedure Call Daemon for managment of network based process communication |
rpcbind | Universal Addresses to RPC Program Number Mapper |
rpm | Policy for the RPM package manager. |
rshd | Remote shell service. |
rssh | Restricted (scp/sftp) only shell |
rsync | Fast incremental file transfer for synchronization |
rtkit | Realtime scheduling for user processes. |
rwho | Who is logged in on other machines? |
samba | SMB and CIFS client/server programs for UNIX and name Service Switch daemon for resolving names from Windows NT servers. |
sambagui | system-config-samba dbus service policy |
samhain | Samhain - check file integrity |
sandbox | policy for sandbox |
sandboxX | policy for sandboxX |
sanlock | policy for sanlock |
sasl | SASL authentication server |
sblim | policy for SBLIM Gatherer |
screen | GNU terminal multiplexer |
sectoolm | Sectool security audit tool |
sendmail | Policy for sendmail. |
sensord | Sensor information logging daemon |
setroubleshoot | SELinux troubleshooting service |
sge | Policy for gridengine MPI jobs |
shorewall | Shoreline Firewall high-level tool for configuring netfilter |
shutdown | System shutdown command |
slocate | Update database for mlocate |
slpd | OpenSLP server daemon to dynamically register services. |
slrnpull | Service for downloading news feeds the slrn newsreader. |
smartmon | Smart disk monitoring daemon policy |
smokeping | Smokeping network latency measurement. |
smoltclient | The Fedora hardware profiler client |
smsd | The SMS Server Tools are made to send and receive short messages through GSM modems. It supports easy file interfaces and it can run external programs for automatic actions. |
snmp | Simple network management protocol services |
snort | Snort network intrusion detection system |
sosreport | sosreport - Generate debugging information for system |
soundserver | sound server for network audio server programs, nasd, yiff, etc |
spamassassin | Filter used for removing unsolicited email. |
speedtouch | Alcatel speedtouch USB ADSL modem |
squid | Squid caching http proxy server |
sssd | System Security Services Daemon |
stapserver | Instrumentation System Server |
stunnel | SSL Tunneling Proxy |
svnserve | policy for svnserve |
sxid | SUID/SGID program monitoring |
sysstat | Policy for sysstat. Reports on various system states |
tcpd | Policy for TCP daemon. |
tcsd | TSS Core Services (TCS) daemon (tcsd) policy |
telepathy | Telepathy communications framework. |
telnet | Telnet daemon |
tftp | Trivial file transfer protocol daemon |
tgtd | Linux Target Framework Daemon. |
thin | thin policy |
thumb | policy for thumb |
thunderbird | Thunderbird email client |
timidity | MIDI to WAV converter and player configured as a service |
tmpreaper | Manage temporary directory sizes and file ages |
tomcat | policy for tomcat |
tor | TOR, the onion router |
transproxy | HTTP transperant proxy |
tripwire | Tripwire file integrity checker. |
tuned | Dynamic adaptive system tuning daemon |
tvtime | tvtime - a high quality television application |
tzdata | Time zone updater |
ucspitcp | ucspitcp policy |
ulogd | Iptables/netfilter userspace logging daemon. |
uml | Policy for UML |
updfstab | Red Hat utility to change /etc/fstab. |
uptime | Uptime daemon |
usbmodules | List kernel modules of USB devices |
usbmuxd | USB multiplexing daemon for communicating with Apple iPod Touch and iPhone |
userhelper | SELinux utility to run a shell with a new role |
usernetctl | User network interface configuration helper |
uucp | Unix to Unix Copy |
uuidd | policy for uuidd |
uwimap | University of Washington IMAP toolkit POP3 and IMAP mail server |
varnishd | Varnishd http accelerator daemon |
vbetool | run real-mode video BIOS code to alter hardware state |
vdagent | policy for vdagent |
vhostmd | Virtual host metrics daemon |
virt | Libvirt virtualization API |
vlock | Lock one or more sessions on the Linux console. |
vmware | VMWare Workstation virtual machines |
vnstatd | Console network traffic monitor. |
vpn | Virtual Private Networking client |
w3c | W3C Markup Validator |
watchdog | Software watchdog |
wdmd | watchdog multiplexing daemon |
webadm | Web administrator role |
webalizer | Web server log analysis |
wine | Wine Is Not an Emulator. Run Windows programs in Linux. |
wireshark | Wireshark packet capture tool. |
wm | X Window Managers |
xen | Xen hypervisor |
xfs | X Windows Font Server |
xguest | Least privledge xwindows user role |
xprint | X print server |
xscreensaver | X Screensaver |
yam | Yum/Apt Mirroring |
zabbix | Distributed infrastructure monitoring |
zarafa | Zarafa collaboration platform. |
zebra | Zebra border gateway protocol network routing service |
zoneminder | policy for zoneminder |
zosremote | policy for z/OS Remote-services Audit dispatcher plugin |