Dominick Grift 98335c8
## <summary>Layer 2 Tunneling Protocol.</summary>
Dominick Grift 98335c8
Dominick Grift 98335c8
########################################
Dominick Grift 98335c8
## <summary>
Dominick Grift 98335c8
##	All of the rules required to
Dominick Grift 98335c8
##	administrate an l2tp environment.
Dominick Grift 98335c8
## </summary>
Dominick Grift 98335c8
## <param name="domain">
Dominick Grift 98335c8
##	<summary>
Dominick Grift 98335c8
##	Domain allowed access.
Dominick Grift 98335c8
##	</summary>
Dominick Grift 98335c8
## </param>
Dominick Grift 98335c8
## <param name="role">
Dominick Grift 98335c8
##	<summary>
Dominick Grift 98335c8
##	Role allowed access.
Dominick Grift 98335c8
##	</summary>
Dominick Grift 98335c8
## </param>
Dominick Grift 98335c8
## <rolecap/>
Dominick Grift 98335c8
#
Dominick Grift 98335c8
interface(`l2tp_admin',`
Dominick Grift 98335c8
	gen_require(`
Dominick Grift 98335c8
		type l2tpd_t, l2tpd_initrc_exec_t, l2tpd_var_run_t;
Dominick Grift 98335c8
		type l2tp_conf_t, l2tpd_tmp_t;
Dominick Grift 98335c8
	')
Dominick Grift 98335c8
Dominick Grift 98335c8
	allow $1 l2tpd_t:process { ptrace signal_perms };
Dominick Grift 98335c8
	ps_process_pattern($1, l2tpd_t)
Dominick Grift 98335c8
Dominick Grift 98335c8
	init_labeled_script_domtrans($1, l2tpd_initrc_exec_t)
Dominick Grift 98335c8
	domain_system_change_exemption($1)
Dominick Grift 98335c8
	role_transition $2 l2tpd_initrc_exec_t system_r;
Dominick Grift 98335c8
	allow $2 system_r;
Dominick Grift 98335c8
Dominick Grift 98335c8
	files_search_etc($1)
Dominick Grift 98335c8
	admin_pattern($1, l2tp_conf_t)
Dominick Grift 98335c8
Dominick Grift 98335c8
	files_search_pids($1)
Dominick Grift 98335c8
	admin_pattern($1, l2tpd_var_run_t)
Dominick Grift 98335c8
Dominick Grift 98335c8
	files_search_tmp($1)
Dominick Grift 98335c8
	admin_pattern($1, l2tpd_tmp_t)
Dominick Grift 98335c8
')