Layer: kernel

Policy for kernel threads, proc filesystem, and unlabeled processes and objects.


Module:Description:
corecommands

Core policy for shells, and generic programs in /bin, /sbin, /usr/bin, and /usr/sbin.

corenetwork

Policy controlling access to network objects

devices

Device nodes and interfaces for many basic system devices.

domain

Core policy for domains.

files

Basic filesystem types and interfaces.

filesystem

Policy for filesystems.

kernel

Policy for kernel threads, proc filesystem, and unlabeled processes and objects.

mcs

Multicategory security policy

mls

Multilevel security policy

selinux

Policy for kernel security interface, in particular, selinuxfs.

storage

Policy controlling access to storage devices

terminal

Policy for terminals.

ubac

User-based access control policy

unlabelednet

Policy for allowing confined domains to use unlabeled_t packets



Layer: roles

Policy modules for user roles.


Module:Description:
auditadm

Audit administrator role

logadm

Log administrator role

secadm

Security administrator role

staff

Administrator's unprivileged user

sysadm

General system administration role

sysadm_secadm

No Interfaces

unconfineduser

Unconfiend user role

unprivuser

Generic unprivileged user



Layer: admin

Policy modules for administrative functions, such as package management.


Module:Description:
bootloader

Policy for the kernel modules, kernel image, and bootloader.

consoletype

Determine of the console connected to the controlling terminal.

dmesg

Policy for dmesg.

netutils

Network analysis utilities

su

Run shells with substitute user and group

sudo

Execute a command with a substitute user

usermanage

Policy for managing user accounts.



Layer: apps

Policy modules for applications


Module:Description:
seunshare

Filesystem namespacing/polyinstantiation application.



Layer: system

Policy modules for system functions from init to multi-user login.


Module:Description:
application

Policy for user executable applications.

authlogin

Common policy for authentication and user login.

clock

Policy for reading and setting the hardware clock.

fstools

Tools for filesystem management, such as mkfs and fsck.

getty

Policy for getty.

hostname

Policy for changing the system host name.

hotplug

Policy for hotplug system, for supporting the connection and disconnection of devices at runtime.

init

System initialization programs (init and init scripts).

ipsec

TCP/IP encryption

iptables

Policy for iptables.

libraries

Policy for system libraries.

locallogin

Policy for local logins.

logging

Policy for the kernel message logger and system logging daemon.

lvm

Policy for logical volume management programs.

miscfiles

Miscelaneous files.

modutils

Policy for kernel module utilities

mount

Policy for mount.

netlabel

NetLabel/CIPSO labeled networking management

selinuxutil

Policy for SELinux policy and userland applications.

setrans

SELinux MLS/MCS label translation service.

sysnetwork

Policy for network configuration: ifconfig and dhcp client.

systemd

SELinux policy for systemd components

udev

Policy for udev.

unconfined

The unconfined domain.

userdomain

Policy for user domains



Layer: services

Policy modules for system services, like cron, and network services, like sshd.


Module:Description:
postgresql

PostgreSQL relational database

ssh

Secure shell client and server policy.

xserver

X Windows Server



Layer: contrib

Contributed Reference Policy modules.


Module:Description:
abrt

ABRT - automated bug-reporting tool

accountsd

AccountsService and daemon for manipulating user account information via D-Bus

acct

Berkeley process accounting

ada

GNAT Ada95 compiler

afs

Andrew Filesystem server

aiccu

Automatic IPv6 Connectivity Client Utility.

aide

Aide filesystem integrity checker

aisexec

Aisexec Cluster Engine

ajaxterm

policy for ajaxterm

alsa

Ainit ALSA configuration tool.

amanda

Advanced Maryland Automatic Network Disk Archiver.

amavis

Daemon that interfaces mail transfer agents and content checkers, such as virus scanners.

amtu

Abstract Machine Test Utility.

anaconda

Anaconda installer.

antivirus

SELinux policy for antivirus programs.

apache

Apache web server

apcupsd

APC UPS monitoring daemon

apm

Advanced power management daemon

apt

APT advanced package tool.

arpwatch

Ethernet activity monitor.

asterisk

Asterisk IP telephony server

authbind

Tool for non-root processes to bind to reserved ports

authconfig

policy for authconfig

automount

Filesystem automounter service.

avahi

mDNS/DNS-SD daemon implementing Apple ZeroConf architecture

awstats

AWStats is a free powerful and featureful tool that generates advanced web, streaming, ftp or mail server statistics, graphically.

backup

System backup scripts

bacula

bacula backup program

bcfg2

bcfg2-server daemon which serves configurations to clients based on the data in its repository

bind

Berkeley internet name domain DNS server.

bitlbee

Bitlbee service

blueman

Blueman is a tool to manage Bluetooth devices

bluetooth

Bluetooth tools and system services.

boinc

policy for boinc

brctl

Utilities for configuring the linux ethernet bridge

bugzilla

Bugzilla server

cachefilesd

policy for cachefilesd

calamaris

Squid log analysis

callweaver

Open source PBX project.

canna

Canna - kana-kanji conversion server

ccs

Cluster Configuration System

cdrecord

Policy for cdrecord

certmaster

Certmaster SSL certificate distribution service

certmonger

Certificate status monitor and PKI enrollment client

certwatch

Digital Certificate Tracking

cfengine

policy for cfengine

cgroup

libcg is a library that abstracts the control group file system in Linux.

chrome

policy for chrome

chronyd

Chrony NTP background daemon

cipe

Encrypted tunnel daemon

clamav

ClamAV Virus Scanner

clockspeed

Clockspeed simple network time protocol client

clogd

clogd - Clustered Mirror Log Server

cloudform

cloudform policy

cmirrord

Cluster mirror log daemon

cobbler

Cobbler installation server.

collectd

policy for collectd

colord

GNOME color manager

comsat

Comsat, a biff server.

condor

policy for condor

consolekit

Framework for facilitating multiple user sessions on desktops.

corosync

Corosync Cluster Engine

couchdb

policy for couchdb

courier

Courier IMAP and POP3 email servers

cpucontrol

Services for loading CPU microcode and CPU frequency scaling.

cpufreqselector

Command-line CPU frequency settings.

cron

Periodic execution of scheduled commands.

ctdbd

policy for ctdbd

cups

Common UNIX printing system

cvs

Concurrent versions system

cyphesis

Cyphesis WorldForge game server

cyrus

Cyrus is an IMAP service intended to be run on sealed servers

daemontools

Collection of tools for managing UNIX services

dante

Dante msproxy and socks4/5 proxy server

dbadm

Database administrator role

dbskk

Dictionary server for the SKK Japanese input method system.

dbus

Desktop messaging bus

dcc

Distributed checksum clearinghouse spam filtering

ddclient

Update dynamic IP address at DynDNS.org

ddcprobe

ddcprobe retrieves monitor and graphics card information

denyhosts

DenyHosts SSH dictionary attack mitigation

devicekit

Devicekit modular hardware abstraction layer

dhcp

Dynamic host configuration protocol (DHCP) server

dictd

Dictionary daemon

dirsrv

policy for dirsrv

dirsrv-admin

Administration Server for Directory Server, dirsrv-admin.

distcc

Distributed compiler daemon

djbdns

small and secure DNS daemon

dkim

DomainKeys Identified Mail milter.

dmidecode

Decode DMI data for x86/ia64 bioses.

dnsmasq

dnsmasq DNS forwarder and DHCP server

dnssec

policy for dnssec_trigger

dovecot

Dovecot POP and IMAP mail server

dpkg

Policy for the Debian package manager.

drbd

policy for drbd

dspam

policy for dspam

entropyd

Generate entropy from audio input

evolution

Evolution email client

exim

Exim mail transfer agent

fail2ban

Update firewall filtering to ban IP addresses with too many password failures.

fcoemon

policy for fcoemon

fetchmail

Remote-mail retrieval and forwarding utility

finger

Finger user information service.

firewalld

policy for firewalld

firewallgui

policy for firewallgui

firstboot

Final system configuration run during the first boot after installation of Red Hat/Fedora systems.

fprintd

DBus fingerprint reader service

ftp

File transfer protocol service

games

Games

gatekeeper

OpenH.323 Voice-Over-IP Gatekeeper

gift

giFT peer to peer file sharing tool

git

GIT revision control system.

gitosis

Tools for managing and hosting git repositories.

glance

policy for glance

glusterd

policy for glusterd

gnome

GNU network object model environment (GNOME)

gnomeclock

Gnome clock handler for setting the time.

gpg

Policy for GNU Privacy Guard and related programs.

gpm

General Purpose Mouse driver

gpsd

gpsd monitor daemon

guest

Least privledge terminal user role

hadoop

Software for reliable, scalable, distributed computing.

hal

Hardware abstraction layer

hddtemp

hddtemp hard disk temperature tool running as a daemon.

howl

Port of Apple Rendezvous multicast DNS

i18n_input

IIIMF htt server

icecast

ShoutCast compatible streaming media server

ifplugd

Bring up/down ethernet interfaces based on cable detection.

imaze

iMaze game server

inetd

Internet services daemon.

inn

Internet News NNTP server

irc

IRC client policy

ircd

IRC server

irqbalance

IRQ balancing daemon

iscsi

Establish connections to iSCSI devices

isnsd

policy for isnsd

jabber

Jabber instant messaging server

java

Java virtual machine

jetty

policy for jetty

jockey

policy for jockey

kde

Policy for KDE components

kdump

Kernel crash dumping mechanism

kdumpgui

system-config-kdump GUI

kerberos

MIT Kerberos admin and KDC

kerneloops

Service for reporting kernel oopses to kerneloops.org

keyboardd

policy for system-setup-keyboard daemon

keystone

policy for keystone

kismet

Kismet is an 802.11 layer2 wireless network detector, sniffer, and intrusion detection system.

ksmtuned

Kernel Samepage Merging (KSM) Tuning Daemon

ktalk

KDE Talk daemon

kudzu

Hardware detection and configuration tools

l2tpd

Layer 2 Tunneling Protocol daemons.

ldap

OpenLDAP directory server

likewise

Likewise Active Directory support for UNIX.

lircd

Linux infared remote control daemon

livecd

Livecd tool for building alternate livecd for different os and policy versions.

lldpad

policy for lldpad

loadkeys

Load keyboard mappings.

lockdev

device locking policy for lockdev

logrotate

Rotate and archive system logs

logwatch

System log analyzer and reporter

lpd

Line printer daemon

mailman

Mailman is for managing electronic mail discussion and e-newsletter lists

mailscanner

E-mail security and anti-spam package for e-mail gateway systems.

man2html

policy for httpd_man2html_script

mandb

policy for mandb

mcelog

policy for mcelog

mediawiki

Mediawiki policy

memcached

high-performance memory object caching system

milter

Milter mail filters

mock

policy for mock

modemmanager

Provides a DBus interface to communicate with mobile broadband (GSM, CDMA, UMTS, ...) cards.

mojomojo

MojoMojo Wiki

mono

Run .NET server and client applications on Linux.

monop

Monopoly daemon

mozilla

Policy for Mozilla and related web browsers

mpd

Music Player Daemon

mplayer

Mplayer media player and encoder

mrtg

Network traffic graphing

mta

Policy common to all email tranfer agents.

munin

Munin network-wide load graphing (formerly LRRD)

mysql

Policy for MySQL

nagios

Net Saint / NAGIOS - network monitoring server

namespace

policy for namespace

ncftool

Netcf network configuration tool (ncftool).

nessus

Nessus network scanning daemon

networkmanager

Manager for dynamically switching between networks.

nis

Policy for NIS (YP) servers and clients

nova

openstack-nova

nscd

Name service cache daemon

nsd

Authoritative only name server

nslcd

nslcd - local LDAP name service daemon.

nsplugin

policy for nsplugin

ntop

Network Top

ntp

Network time protocol daemon

numad

policy for numad

nut

nut - Network UPS Tools

nx

NX remote desktop

oav

Open AntiVirus scannerdaemon and signature update

obex

SELinux policy for obex-data-server

oddjob

Oddjob provides a mechanism by which unprivileged applications can request that specified privileged operations be performed on their behalf.

oident

SELinux policy for Oident daemon.

openca

OpenCA - Open Certificate Authority

openct

Service for handling smart card readers.

openhpid

policy for openhpid

openshift

policy for openshift

openshift-origin
openvpn

full-featured SSL VPN solution

openvswitch

policy for openvswitch

pacemaker

policy for pacemaker

pads

Passive Asset Detection System

passenger

Ruby on rails deployment for Apache and Nginx servers.

pcmcia

PCMCIA card management services

pcscd

PCSC smart card service

pegasus

The Open Group Pegasus CIM/WBEM Server.

perdition

Perdition POP and IMAP proxy

phpfpm

PHP-FPM (FastCGI Process Manager) is an alternative PHP FastCGI implementation with some additional features useful for sites of any size, especially busier sites.

pingd

Pingd of the Whatsup cluster node up/down detection utility

piranha

policy for piranha

pkcsslotd

policy for pkcsslotd

pki

policy for pki

plymouthd

Plymouth graphical boot

podsleuth

Podsleuth is a tool to get information about an Apple (TM) iPod (TM)

policykit

Policy framework for controlling privileges for system-wide services.

polipo

Caching web proxy.

portage

Portage Package Management System. The primary package management and distribution system for Gentoo.

portmap

RPC port mapping service.

portreserve

Reserve well-known ports in the RPC port range.

portslave

Portslave terminal server software

postfix

Postfix email server

postfixpolicyd

Postfix policy server

postgrey

Postfix grey-listing server

ppp

Point to Point Protocol daemon creates links in ppp networks

prelink

Prelink ELF shared library mappings.

prelude

Prelude hybrid intrusion detection system

privoxy

Privacy enhancing web proxy.

procmail

Procmail mail delivery agent

psad

Intrusion Detection and Log Analysis with iptables

ptchown

helper function for grantpt(3), changes ownship and permissions of pseudotty

publicfile

publicfile supplies files to the public through HTTP and FTP

pulseaudio

Pulseaudio network sound server.

puppet

Puppet client daemon

pwauth

policy for pwauth

pxe

Server for the PXE network boot protocol

pyicqt

PyICQt is an ICQ transport for XMPP server.

pyzor

Pyzor is a distributed, collaborative spam detection and filtering network.

qemu

QEMU machine emulator and virtualizer

qmail

Qmail Mail Server

qpid

policy for qpidd

quantum

Quantum is a virtual network service for Openstack

quota

File system quota management

rabbitmq

policy for rabbitmq

radius

RADIUS authentication and accounting server.

radvd

IPv6 router advertisement daemon

raid

RAID array management tools

razor

A distributed, collaborative, spam detection and filtering network.

rdisc

Network router discovery daemon

readahead

Readahead, read files into page cache for improved performance

realmd

dbus system service which manages discovery and enrollment in realms and domains like Active Directory or IPA

remotelogin

Policy for rshd, rlogind, and telnetd.

resmgr

Resource management daemon

rgmanager

rgmanager - Resource Group Manager

rhcs

RHCS - Red Hat Cluster Suite

rhev

rhev polic module contains policies for rhev apps

rhgb

Red Hat Graphical Boot

rhnsd

policy for rhnsd

rhsmcertd

Subscription Management Certificate Daemon policy

ricci

Ricci cluster management agent

rlogin

Remote login daemon

rngd

Check and feed random data from hardware device to kernel random device.

roundup

Roundup Issue Tracking System policy

rpc

Remote Procedure Call Daemon for managment of network based process communication

rpcbind

Universal Addresses to RPC Program Number Mapper

rpm

Policy for the RPM package manager.

rshd

Remote shell service.

rssh

Restricted (scp/sftp) only shell

rsync

Fast incremental file transfer for synchronization

rtkit

Realtime scheduling for user processes.

rwho

Who is logged in on other machines?

samba

SMB and CIFS client/server programs for UNIX and name Service Switch daemon for resolving names from Windows NT servers.

sambagui

system-config-samba dbus service policy

samhain

Samhain - check file integrity

sandbox

policy for sandbox

sandboxX

policy for sandboxX

sanlock

policy for sanlock

sasl

SASL authentication server

sblim

policy for SBLIM Gatherer

screen

GNU terminal multiplexer

sectoolm

Sectool security audit tool

sendmail

Policy for sendmail.

sensord

Sensor information logging daemon

setroubleshoot

SELinux troubleshooting service

sge

Policy for gridengine MPI jobs

shorewall

Shoreline Firewall high-level tool for configuring netfilter

shutdown

System shutdown command

slocate

Update database for mlocate

slpd

OpenSLP server daemon to dynamically register services.

slrnpull

Service for downloading news feeds the slrn newsreader.

smartmon

Smart disk monitoring daemon policy

smokeping

Smokeping network latency measurement.

smoltclient

The Fedora hardware profiler client

smsd

The SMS Server Tools are made to send and receive short messages through GSM modems. It supports easy file interfaces and it can run external programs for automatic actions.

snmp

Simple network management protocol services

snort

Snort network intrusion detection system

sosreport

sosreport - Generate debugging information for system

soundserver

sound server for network audio server programs, nasd, yiff, etc

spamassassin

Filter used for removing unsolicited email.

speedtouch

Alcatel speedtouch USB ADSL modem

squid

Squid caching http proxy server

sssd

System Security Services Daemon

stapserver

Instrumentation System Server

stunnel

SSL Tunneling Proxy

svnserve

policy for svnserve

sxid

SUID/SGID program monitoring

sysstat

Policy for sysstat. Reports on various system states

tcpd

Policy for TCP daemon.

tcsd

TSS Core Services (TCS) daemon (tcsd) policy

telepathy

Telepathy communications framework.

telnet

Telnet daemon

tftp

Trivial file transfer protocol daemon

tgtd

Linux Target Framework Daemon.

thin

thin policy

thumb

policy for thumb

thunderbird

Thunderbird email client

timidity

MIDI to WAV converter and player configured as a service

tmpreaper

Manage temporary directory sizes and file ages

tomcat

policy for tomcat

tor

TOR, the onion router

transproxy

HTTP transperant proxy

tripwire

Tripwire file integrity checker.

tuned

Dynamic adaptive system tuning daemon

tvtime

tvtime - a high quality television application

tzdata

Time zone updater

ucspitcp

ucspitcp policy

ulogd

Iptables/netfilter userspace logging daemon.

uml

Policy for UML

updfstab

Red Hat utility to change /etc/fstab.

uptime

Uptime daemon

usbmodules

List kernel modules of USB devices

usbmuxd

USB multiplexing daemon for communicating with Apple iPod Touch and iPhone

userhelper

SELinux utility to run a shell with a new role

usernetctl

User network interface configuration helper

uucp

Unix to Unix Copy

uuidd

policy for uuidd

uwimap

University of Washington IMAP toolkit POP3 and IMAP mail server

varnishd

Varnishd http accelerator daemon

vbetool

run real-mode video BIOS code to alter hardware state

vdagent

policy for vdagent

vhostmd

Virtual host metrics daemon

virt

Libvirt virtualization API

vlock

Lock one or more sessions on the Linux console.

vmware

VMWare Workstation virtual machines

vnstatd

Console network traffic monitor.

vpn

Virtual Private Networking client

w3c

W3C Markup Validator

watchdog

Software watchdog

wdmd

watchdog multiplexing daemon

webadm

Web administrator role

webalizer

Web server log analysis

wine

Wine Is Not an Emulator. Run Windows programs in Linux.

wireshark

Wireshark packet capture tool.

wm

X Window Managers

xen

Xen hypervisor

xfs

X Windows Font Server

xguest

Least privledge xwindows user role

xprint

X print server

xscreensaver

X Screensaver

yam

Yum/Apt Mirroring

zabbix

Distributed infrastructure monitoring

zarafa

Zarafa collaboration platform.

zebra

Zebra border gateway protocol network routing service

zoneminder

policy for zoneminder

zosremote

policy for z/OS Remote-services Audit dispatcher plugin