Samhain - check file integrity
All of the rules required to administrate the samhain environment.
This interface assumes that the calling domain has been able to remove an entry from /var/lib/ or /var/log/ and belongs to the mlsfilewrite attribute, since samhain files may be of clearance security level while their parent directories are of s0.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute samhain in the samhain domain
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Manage samhain configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage samhain database files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage samhain init script files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage samhain log and log.lock files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage samhain pid files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute samhain in the samhain domain with the clearance security level and allow the specifiled role the samhain domain.
Execute samhain in the samhain domain with the clearance security level and allow the specifiled role the samhain domain.
The range_transition rule used in this interface requires that the calling domain should have the clearance security level otherwise the MLS constraint for process transition would fail.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
Role allowed to access. |
The template containing the most basic rules common to the samhain domains.
Parameter: | Description: |
---|---|
samhaindomain_prefix |
The prefix of the samhain domains(e.g., samhain for the domain of command line access, samhaind for the domain started by init script). |