Policy common to all email tranfer agents.
Make the specified type a MTA executable file.
| Parameter: | Description: |
|---|---|
| type |
Type to be used as a mail client. |
ALlow domain to append mail content in the homedir
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, and write the mail spool.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Delete from the mail spool.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Do not audit attempts to get the attributes of mail spool files.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Dontaudit read and write an leaked file descriptors
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read a symlink in the mail spool.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read and write TCP sockets of mail delivery domains.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read and write the mail queue.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Type transition files created in /etc to the mail address aliases type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| name |
The name of the object being created. |
create mail content in the in the /root directory with an correct label.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Type transition files created in calling dir to the mail address aliases type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| domain |
Directory to transition on. |
Transition to mta named home content
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Transition to mta named content
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Get the attributes of mail spool files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Send system mail client a kill signal
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Send all user mail client a kill signal
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
List the mail queue.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Make the specified domain usable for a mail server.
| Parameter: | Description: |
|---|---|
| type |
Type to be used as a mail server domain. |
| entry_point |
Type of the program to be used as an entry point to this domain. |
Make a type a mailserver type used for delivering mail to local users.
| Parameter: | Description: |
|---|---|
| domain |
Mail server domain type used for delivering mail. |
Make a type a mailserver type used for sending mail.
| Parameter: | Description: |
|---|---|
| domain |
Mail server domain type used for sending mail. |
Make a type a mailserver type used for sending mail on behalf of local users to the local mail spool.
| Parameter: | Description: |
|---|---|
| domain |
Mail server domain type used for sending local mail. |
Create, read, write, and delete mail address aliases.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage mail server configuration.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow domain to manage mail content in the homedir
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, write, and delete mail queue files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, write, and delete mail spool files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read mail address aliases.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read mail server configuration.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
ALlow domain to read mail content in the homedir
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
ALlow domain to read mail content in the homedir
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read the mail queue.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read sendmail binary.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read the mail spool.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Role access for mta
| Parameter: | Description: |
|---|---|
| role |
Role allowed access |
| domain |
User domain for the role |
Allow role to access system_mail_t.
| Parameter: | Description: |
|---|---|
| role |
Role allowed access. |
Read and write mail aliases.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow attempts to read and write TCP sockets of mail delivery domains.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Read and write the mail spool.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read and write unix domain stream sockets of user mail domains.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Search mail queue dirs.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Send mail from the system.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
Check whether sendmail executable files are executable.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Execute send mail in a specified domain.
Execute send mail in a specified domain.
No interprocess communication (signals, pipes, etc.) is provided by this interface since the domains are not owned by this module.
| Parameter: | Description: |
|---|---|
| source_domain |
Domain allowed to transition. |
| target_domain |
Domain to transition to. |
Execute sendmail in the caller domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Modified mailserver interface for sendmail daemon use.
A modified MTA mail server interface for the sendmail program. It's design does not fit well with policy, and using the regular interface causes a type_transition conflict if direct running of init scripts is enabled.
This interface should most likely only be used by the sendmail policy.
| Parameter: | Description: |
|---|---|
| domain |
The type to be used for the mail server. |
Send system mail client a signal
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Send all user mail client a signal
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create private objects in the mail spool directory.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| private type |
The type of the object to be created. |
| object |
The object class of the object being created. |
| name |
The name of the object being created. |
Create private objects in the mqueue spool directory.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| private type |
The type of the object to be created. |
| object |
The object class of the object being created. |
| name |
The name of the object being created. |
MTA stub interface. No access allowed.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Make the specified type by a system MTA.
| Parameter: | Description: |
|---|---|
| type |
Type to be used as a mail client. |
Connect to all mail servers over TCP. (Deprecated)
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
write mail server configuration.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Basic mail transfer agent domain template.
This template creates a derived domain which is a email transfer agent, which sends mail on behalf of the user.
This is the basic types and rules, common to the system agent and user agents.
| Parameter: | Description: |
|---|---|
| domain_prefix |
The prefix of the domain (e.g., user is the prefix for user_t). |