Changes to the certmaster policy module and various role attribute fixes
Ported from Fedora with changes
init system domains already have access to system_r role
do not allow application domains access to system_r role if they do not
need it
Signed-off-by: Dominick Grift <dominick.grift@gmail.com>