Common e-mail transfer agent policy.
Make the specified type a MTA executable file.
| Parameter: | Description: |
|---|---|
| type |
Type to be used as a mail client. |
Create, read, and write mail spool files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Delete mail spool files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Do not audit attempts to get attributes of mail spool files.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read mail spool symlinks.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read and write TCP sockets of mail delivery domains.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read and write mail queue content.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Create specified object in generic etc directories with the mail address alias type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| object |
The object class of the object being created. |
| name |
The name of the object being created. |
Get attributes of mail spool content.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create specified objects in user home directories with the generic mail home type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| object_class |
Class of the object being created. |
| name |
The name of the object being created. |
Create specified objects in user home directories with the generic mail home rw type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| object_class |
Class of the object being created. |
| name |
The name of the object being created. |
Send kill signals to system mail.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
List mail queue directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow listing the mail spool.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Make the specified domain usable for a mail server.
| Parameter: | Description: |
|---|---|
| type |
Type to be used as a mail server domain. |
| entry_point |
Type of the program to be used as an entry point to this domain. |
Make a type a mailserver type used for delivering mail to local users.
| Parameter: | Description: |
|---|---|
| domain |
Mail server domain type used for delivering mail. |
Make a type a mailserver type used for sending mail.
| Parameter: | Description: |
|---|---|
| domain |
Mail server domain type used for sending mail. |
Make a type a mailserver type used for sending mail on behalf of local users to the local mail spool.
| Parameter: | Description: |
|---|---|
| domain |
Mail server domain type used for sending local mail. |
Create, read, write, and delete mail address alias content.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, write, and delete mail server configuration content.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, write, and delete mta mail home files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, write, and delete mta mail home rw content.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, write, and delete mail queue content.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, write, and delete mail spool content.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read mail address alias files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create specified objects in the mail queue spool directory with a private type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| private type |
The type of the object to be created. |
| object |
The object class of the object being created. |
| name |
The name of the object being created. |
Read mail address alias files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read mail server configuration content.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read mta mail home files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read mail queue files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read sendmail binary.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read mail spool files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow reading mail spool symlinks.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Read and write mail alias files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
read and write fifo files inherited from delivery domains
| Parameter: | Description: |
|---|---|
| domain |
Domain to use fifo files |
Read and write mail spool files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read and write unix domain stream sockets of all base mail domains.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Search mail queue directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Send mail from the system.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
Execute send mail in a specified domain.
Execute send mail in a specified domain.
No interprocess communication (signals, pipes, etc.) is provided by this interface since the domains are not owned by this module.
| Parameter: | Description: |
|---|---|
| source_domain |
Domain allowed to transition. |
| target_domain |
Domain to transition to. |
Make sendmail usable as an entry point for the domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain to be entered. |
Execute sendmail in the caller domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Modified mailserver interface for sendmail daemon use.
A modified MTA mail server interface for the sendmail program. It's design does not fit well with policy, and using the regular interface causes a type_transition conflict if direct running of init scripts is enabled.
This interface should most likely only be used by the sendmail policy.
| Parameter: | Description: |
|---|---|
| domain |
The type to be used for the mail server. |
Send signals to system mail.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create specified objects in specified directories with a type transition to the mail address alias type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| file_type |
Directory to transition on. |
| object |
The object class of the object being created. |
| name |
The name of the object being created. |
Create specified objects in the mail spool directory with a private type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| private type |
The type of the object to be created. |
| object |
The object class of the object being created. |
| name |
The name of the object being created. |
MTA stub interface. No access allowed.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Make the specified type by a system MTA.
| Parameter: | Description: |
|---|---|
| type |
Type to be used as a mail client. |
Allow system_mail_t to run in a role
| Parameter: | Description: |
|---|---|
| domain |
Role allowed access. |
Inherit FDs from mailserver_domain domains
| Parameter: | Description: |
|---|---|
| type |
Type for a list server or delivery agent that inherits fds |
Watch mail spool content.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Write mail server configuration files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
The template to define a mail domain.
| Parameter: | Description: |
|---|---|
| domain_prefix |
Domain prefix to be used. |
Role access for mta.
| Parameter: | Description: |
|---|---|
| role_prefix |
The prefix of the user role (e.g., user is the prefix for user_r). |
| user_domain |
User domain for the role. |
| user_exec_domain |
User exec domain for execute and transition access. |
| role |
Role allowed access |