1mozilla_plugin_config_SsEeLliinnuuxx(P8o)licy mozilla_plumgoizni_lcloan_fpilgugin_config_selinux(8)
2
3
4

NAME

6       mozilla_plugin_config_selinux  - Security Enhanced Linux Policy for the
7       mozilla_plugin_config processes
8

DESCRIPTION

10       Security-Enhanced Linux secures the mozilla_plugin_config processes via
11       flexible mandatory access control.
12
13       The  mozilla_plugin_config  processes  execute  with  the mozilla_plug‐
14       in_config_t SELinux type. You can check if  you  have  these  processes
15       running by executing the ps command with the -Z qualifier.
16
17       For example:
18
19       ps -eZ | grep mozilla_plugin_config_t
20
21
22

ENTRYPOINTS

24       The  mozilla_plugin_config_t  SELinux  type  can  be  entered  via  the
25       mozilla_plugin_config_exec_t file type.
26
27       The default entrypoint paths for the mozilla_plugin_config_t domain are
28       the following:
29
30       /usr/lib/nspluginwrapper/plugin-config
31

PROCESS TYPES

33       SELinux defines process types (domains) for each process running on the
34       system
35
36       You can see the context of a process using the -Z option to ps
37
38       Policy governs the access confined processes have  to  files.   SELinux
39       mozilla_plugin_config  policy  is very flexible allowing users to setup
40       their mozilla_plugin_config processes in as secure a method  as  possi‐
41       ble.
42
43       The following process types are defined for mozilla_plugin_config:
44
45       mozilla_plugin_config_t
46
47       Note:  semanage  permissive  -a  mozilla_plugin_config_t can be used to
48       make the process type mozilla_plugin_config_t permissive. SELinux  does
49       not  deny  access  to  permissive  process  types, but the AVC (SELinux
50       denials) messages are still generated.
51
52

BOOLEANS

54       SELinux  policy  is  customizable  based  on  least  access   required.
55       mozilla_plugin_config  policy  is  extremely  flexible  and has several
56       booleans that allow you to manipulate the policy and run  mozilla_plug‐
57       in_config with the tightest access possible.
58
59
60
61       If you want to allow users to resolve user passwd entries directly from
62       ldap rather then using a sssd server, you  must  turn  on  the  authlo‐
63       gin_nsswitch_use_ldap boolean. Disabled by default.
64
65       setsebool -P authlogin_nsswitch_use_ldap 1
66
67
68
69       If  you  want  to deny any process from ptracing or debugging any other
70       processes, you  must  turn  on  the  deny_ptrace  boolean.  Enabled  by
71       default.
72
73       setsebool -P deny_ptrace 1
74
75
76
77       If  you  want  to  allow  any  process  to mmap any file on system with
78       attribute file_type, you must turn on the  domain_can_mmap_files  bool‐
79       ean. Enabled by default.
80
81       setsebool -P domain_can_mmap_files 1
82
83
84
85       If  you want to allow all domains write to kmsg_device, while kernel is
86       executed with systemd.log_target=kmsg parameter, you must turn  on  the
87       domain_can_write_kmsg boolean. Disabled by default.
88
89       setsebool -P domain_can_write_kmsg 1
90
91
92
93       If you want to allow all domains to use other domains file descriptors,
94       you must turn on the domain_fd_use boolean. Enabled by default.
95
96       setsebool -P domain_fd_use 1
97
98
99
100       If you want to allow all domains to have the kernel load  modules,  you
101       must  turn  on  the  domain_kernel_load_modules  boolean.  Disabled  by
102       default.
103
104       setsebool -P domain_kernel_load_modules 1
105
106
107
108       If you want to allow all domains to execute in fips_mode, you must turn
109       on the fips_mode boolean. Enabled by default.
110
111       setsebool -P fips_mode 1
112
113
114
115       If you want to enable reading of urandom for all domains, you must turn
116       on the global_ssp boolean. Disabled by default.
117
118       setsebool -P global_ssp 1
119
120
121
122       If you want to allow confined applications to run  with  kerberos,  you
123       must turn on the kerberos_enabled boolean. Enabled by default.
124
125       setsebool -P kerberos_enabled 1
126
127
128
129       If  you  want  to  allow  system  to run with NIS, you must turn on the
130       nis_enabled boolean. Disabled by default.
131
132       setsebool -P nis_enabled 1
133
134
135
136       If you want to allow confined applications to use nscd  shared  memory,
137       you must turn on the nscd_use_shm boolean. Disabled by default.
138
139       setsebool -P nscd_use_shm 1
140
141
142
143       If  you  want  to  allow  unconfined users to transition to the Mozilla
144       plugin domain when running xulrunner plugin-container, you must turn on
145       the unconfined_mozilla_plugin_transition boolean. Enabled by default.
146
147       setsebool -P unconfined_mozilla_plugin_transition 1
148
149
150
151       If  you want to support ecryptfs home directories, you must turn on the
152       use_ecryptfs_home_dirs boolean. Disabled by default.
153
154       setsebool -P use_ecryptfs_home_dirs 1
155
156
157

MANAGED FILES

159       The SELinux  process  type  mozilla_plugin_config_t  can  manage  files
160       labeled  with  the  following  file  types.   The  paths listed are the
161       default paths for these file types.  Note the processes UID still  need
162       to have DAC permissions.
163
164       mozilla_home_t
165
166            /home/[^/]+/.lyx(/.*)?
167            /home/[^/]+/.java(/.*)?
168            /home/[^/]+/.adobe(/.*)?
169            /home/[^/]+/.gnash(/.*)?
170            /home/[^/]+/.webex(/.*)?
171            /home/[^/]+/.galeon(/.*)?
172            /home/[^/]+/.spicec(/.*)?
173            /home/[^/]+/.IBMERS(/.*)?
174            /home/[^/]+/POkemon.*(/.*)?
175            /home/[^/]+/.mozilla(/.*)?
176            /home/[^/]+/.phoenix(/.*)?
177            /home/[^/]+/.icedtea(/.*)?
178            /home/[^/]+/.netscape(/.*)?
179            /home/[^/]+/.quakelive(/.*)?
180            /home/[^/]+/.ICAClient(/.*)?
181            /home/[^/]+/.macromedia(/.*)?
182            /home/[^/]+/.thunderbird(/.*)?
183            /home/[^/]+/.gcjwebplugin(/.*)?
184            /home/[^/]+/.grl-podcasts(/.*)?
185            /home/[^/]+/.cache/mozilla(/.*)?
186            /home/[^/]+/.icedteaplugin(/.*)?
187            /home/[^/]+/zimbrauserdata(/.*)?
188            /home/[^/]+/.config/chromium(/.*)?
189            /home/[^/]+/.juniper_networks(/.*)?
190            /home/[^/]+/.cache/icedtea-web(/.*)?
191            /home/[^/]+/abc
192            /home/[^/]+/mozilla.pdf
193            /home/[^/]+/.gnashpluginrc
194
195       mozilla_plugin_rw_t
196
197            /usr/lib/mozilla/plugins-wrapped(/.*)?
198
199       mozilla_plugin_tmp_t
200
201
202       user_fonts_cache_t
203
204            /root/.fontconfig(/.*)?
205            /root/.fonts/auto(/.*)?
206            /root/.fonts.cache-.*
207            /home/[^/]+/.fontconfig(/.*)?
208            /home/[^/]+/.fonts/auto(/.*)?
209            /home/[^/]+/.fonts.cache-.*
210
211

FILE CONTEXTS

213       SELinux requires files to have an extended attribute to define the file
214       type.
215
216       You can see the context of a file using the -Z option to ls
217
218       Policy governs the access  confined  processes  have  to  these  files.
219       SELinux mozilla_plugin_config policy is very flexible allowing users to
220       setup their mozilla_plugin_config processes in as secure  a  method  as
221       possible.
222
223       The following file types are defined for mozilla_plugin_config:
224
225
226
227       mozilla_plugin_config_exec_t
228
229       -  Set files with the mozilla_plugin_config_exec_t type, if you want to
230       transition an executable to the mozilla_plugin_config_t domain.
231
232
233
234       Note: File context can be temporarily modified with the chcon  command.
235       If  you want to permanently change the file context you need to use the
236       semanage fcontext command.  This will modify the SELinux labeling data‐
237       base.  You will need to use restorecon to apply the labels.
238
239

COMMANDS

241       semanage  fcontext  can also be used to manipulate default file context
242       mappings.
243
244       semanage permissive can also be used to manipulate  whether  or  not  a
245       process type is permissive.
246
247       semanage  module can also be used to enable/disable/install/remove pol‐
248       icy modules.
249
250       semanage boolean can also be used to manipulate the booleans
251
252
253       system-config-selinux is a GUI tool available to customize SELinux pol‐
254       icy settings.
255
256

AUTHOR

258       This manual page was auto-generated using sepolicy manpage .
259
260

SEE ALSO

262       selinux(8),   mozilla_plugin_config(8),   semanage(8),   restorecon(8),
263       chcon(1), sepolicy(8) , setsebool(8)
264
265
266
267mozilla_plugin_config              19-04-25   mozilla_plugin_config_selinux(8)
Impressum