Apache web server
false
Allow Apache to modify public files used for public file transfer services. Directories/Files must be labeled public_content_rw_t.
false
Allow httpd to use built in scripting (usually php)
false
Allow http daemon to check spam
false
Allow httpd to act as a FTP client connecting to the ftp port and ephemeral ports
false
Allow httpd to connect to the ldap port
false
Allow http daemon to connect to mythtv
false
Allow http daemon to connect to zabbix
false
Allow HTTPD scripts and modules to connect to the network using TCP.
false
Allow HTTPD scripts and modules to connect to cobbler over the network.
false
Allow HTTPD scripts and modules to connect to databases over the network.
false
Allow httpd to connect to memcache server
false
Allow httpd to act as a relay
false
Allow http daemon to send mail
false
Allow Apache to communicate with avahi service via dbus
false
Allow Apache to communicate with sssd service via dbus
false
Dontaudit Apache to search dirs.
false
Allow httpd cgi support
false
Allow httpd to act as a FTP server by listening on the ftp port.
false
Allow httpd to read home directories
false
Allow httpd scripts and modules execmem/execstack
false
Allow HTTPD to connect to port 80 for graceful shutdown
false
Allow httpd processes to manage IPA content
false
Allow Apache to use mod_auth_ntlm_winbind
false
Allow Apache to use mod_auth_pam
false
Allow httpd to read user content
false
Allow httpd processes to run IPA helper.
false
Allow Apache to run preupgrade
false
Allow Apache to run in stickshift mode, not transition to passenger
false
Allow HTTPD scripts and modules to server cobbler files.
false
Allow httpd daemon to change its resource limits
false
Allow HTTPD to run SSI executables in the same domain as system CGI scripts.
false
Allow apache scripts to write to public content, directories/files must be labeled public_rw_content_t.
false
Allow Apache to execute tmp content.
false
Unify HTTPD to communicate with the terminal. Needed for entering the passphrase for certificates at the terminal.
false
Unify HTTPD handling of all content files.
false
Allow httpd to access cifs file systems
false
Allow httpd to access FUSE file systems
false
Allow httpd to run gpg
false
Allow httpd to access nfs file systems
false
Allow httpd to access openstack ports
false
Allow httpd to connect to sasl
false
Allow Apache to query NS records
All of the rules required to administrate an apache environment
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
Role allowed access. |
Allow the specified domain to append to apache log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to append apache squirrelmail data.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute CGI in the specified domain.
Execute CGI in the specified domain.
This is an interface to support third party modules and its use is not allowed in upstream reference policy.
Parameter: | Description: |
---|---|
domain |
Domain run the cgi script in. |
entrypoint |
Type of the executable to enter the cgi domain. |
Send and receive messages from httpd over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to delete Apache cache dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to delete Apache cache.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to delete apache system content rw files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to apache.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute all user scripts in the user script domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute the Apache helper program with a domain transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a domain transition to run httpd_rotatelogs.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute all web scripts in the system script domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Do not audit attempts to append to the Apache logs.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
dontaudit read and write an leaked file descriptors
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
dontaudit attempts to read apache log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Do not audit attempts to read and write Apache unnamed pipes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write Apache unix domain stream sockets.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write Apache system script unix domain stream sockets.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write Apache TCP sockets.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit attempts to read and write apache tmp files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to search Apache module directories.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit attempts to write apache tmp files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Allow any httpd_exec_t to be an entrypoint of this domain
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to execute apache in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a httpd_exec_t in the specified domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
target_domain |
The type of the new process. |
Allow the specified domain to execute apache modules.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute httpd_rotatelogs in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Allow the specified domain to execute apache suexec in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute httpd system scripts in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Transition to apache home content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to apache named content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to list Apache cache.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to list the contents of the apache modules directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to list apache system content files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete all web content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete all user web content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to manage apache configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to manage to apache var lib files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to manage to apache log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to manage apache system content files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to manage apache system content rw files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage user web content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read apache configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read apache log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read the apache module directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read apache pid files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read apache squirrelmail data.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read apache system content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read apache system content rw dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read apache system content rw files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read apache tmp files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read user web content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read httpd user scripts executables.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Role access for apache
Parameter: | Description: |
---|---|
role |
Role allowed access |
domain |
User domain for the role |
Execute all user scripts in the user script domain. Add user script domains to the specified role.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
Role allowed access. |
Execute the Apache helper program with a domain transition, and allow the specified role the Apache helper domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
Role allowed access. |
Allow the specified domain to read and write Apache cache files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow attempts to read and write Apache unix domain stream sockets.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Allow the specified domain to search apache configuration dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search apache system content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search system script state directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search apache system CGI directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to set the attributes of the APACHE cache directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send a SIGCHLD signal to apache.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send a generic signal to apache.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send a null signal to apache.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute httpd server in the httpd domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Inherit and use file descriptors from Apache.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to write to apache log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create a set of derived types for apache web content.
Parameter: | Description: |
---|---|
prefix |
The prefix to be used for deriving new type names. |
oldprefix |
The prefix to be used for deriving old type names. |
Create a set of derived types for apache web content.
Parameter: | Description: |
---|---|
prefix |
The prefix to be used for deriving type names. |
Create a set of derived types for apache web content.
Parameter: | Description: |
---|---|
prefix |
The prefix to be used for deriving type names. |