From 9aa2bb3bcd3ec45c8e9c36e383105f22cff314d1 Mon Sep 17 00:00:00 2001 From: Dominick Grift Date: Sep 27 2012 08:30:13 +0000 Subject: Modify dbadm boolean descriptions Signed-off-by: Dominick Grift --- diff --git a/dbadm.if b/dbadm.if index 56f2af7..d9ed651 100644 --- a/dbadm.if +++ b/dbadm.if @@ -1,4 +1,4 @@ -## Database administrator role +## Database administrator role. ######################################## ## diff --git a/dbadm.te b/dbadm.te index 1875064..0e74996 100644 --- a/dbadm.te +++ b/dbadm.te @@ -1,4 +1,4 @@ -policy_module(dbadm, 1.0.0) +policy_module(dbadm, 1.0.1) ######################################## # @@ -6,16 +6,18 @@ policy_module(dbadm, 1.0.0) # ## -##

-## Allow dbadm to manage files in users home directories -##

+##

+## Determine whether dbadm can manage +## files in users home directories. +##

##
gen_tunable(dbadm_manage_user_files, false) ## -##

-## Allow dbadm to read files in users home directories -##

+##

+## Determine whether dbadm can read +## files in users home directories. +##

##
gen_tunable(dbadm_read_user_files, false) @@ -25,7 +27,7 @@ userdom_base_user_template(dbadm) ######################################## # -# database admin local policy +# Local policy # allow dbadm_t self:capability { dac_override dac_read_search sys_ptrace };