Layer: system

Module: locallogin

Tunables Interfaces

Description:

Policy for local logins.


Tunables:

local_login_allow_accountutils_fallback_mode
Default value

true

Description

Allow accountutils fallback to be able to directly access /etc/shadow. This will cause older pam_unix to fail the login as they are checking if an caller's domain is confined by checking the access to /etc/shadow. See also: https://github.com/linux-pam/linux-pam/blob/d74c4294d32cffcf5dbc7a4491142877471b98a0/modules/pam_unix/passverify.c#L557

local_login_containers
Default value

false

Description

Allow login console run podman

Return

Interfaces:

locallogin_domtrans( domain )
Summary

Execute local logins in the local login domain.

Parameters
Parameter:Description:
domain

Domain allowed to transition.

locallogin_domtrans_sulogin( domain )
Summary

Execute local logins in the local login domain.

Parameters
Parameter:Description:
domain

Domain allowed to transition.

locallogin_dontaudit_use_fds( domain )
Summary

Do not audit attempts to inherit local login file descriptors.

Parameters
Parameter:Description:
domain

Domain to not audit.

locallogin_filetrans_admin_home_content( domain )
Summary

create local login content in the in the /root directory with an correct label.

Parameters
Parameter:Description:
domain

Domain allowed access.

locallogin_filetrans_home_content( domain )
Summary

Transition to local login named content

Parameters
Parameter:Description:
domain

Domain allowed access.

locallogin_getattr_home_content( domain )
Summary

Allow domain to gettatr local login home content

Parameters
Parameter:Description:
domain

Domain allowed access.

locallogin_link_keys( domain )
Summary

Allow link to the local_login key ring.

Parameters
Parameter:Description:
domain

Domain allowed access.

locallogin_search_keys( domain )
Summary

Search for key.

Parameters
Parameter:Description:
domain

Domain allowed access.

locallogin_signull( domain )
Summary

Send a null signal to local login processes.

Parameters
Parameter:Description:
domain

Domain allowed access.

locallogin_use_fds( domain )
Summary

Allow processes to inherit local login file descriptors.

Parameters
Parameter:Description:
domain

Domain allowed access.

Return