Viewing File: /usr/share/locale/ja/LC_MESSAGES/policycoreutils.mo

Þ•ŽŒ%G\Kxd,yd%ŠdÌdàdôde'e@ePe?ge;§e&ãe9
fDf9af,›f7ÈfgIgI_gI©g3óg'h+h 4h'Uh,}hªhEŸh:i(?i.hi,—iÄi×i&éi/j.@j&oj0–j/ÇjS÷j8Kk„k“k¯kÂkÓk7äkdl^lèàl)Émónúnþnoo
%o3o<oMMo›oMŽopHpG]p¥p¶pGÎpq3qMqgqxqQ‘qãqõqJþq
IrNTr£rŒrÕr4çr$s!As%csM‰s×sès)ñs/tKtbtrttœtšt»tÎtÒt>ÞtIu7gu6Ÿu$Öu‚ûu ~vCŸvãv)w ,wGMwI•wDßw8$x7]xL•x-âxCy7TyŒyO©y ùy-z5Hz&~z)¥z)Ïz1ùz7+{hc{pÌ{?=|=}|>»|Fú|gA}©}UÈ}I~Eh~1®~6à~M<e:¢:Ý2€1K€0}€K®€-ú€H(0q:¢ ݁þ.‚J‚<f‚&£‚&ʂ(ñ‚Aƒ0\ƒ‡ƒ7„8M„S†„Jڄ%…A…&a…&ˆ…¯…΅0æ…+†(C†1l†'ž†'Ɔ&î†%‡Q;‡@‡·ì‡)ˆ'6ˆ$^ˆ ƒˆ€ˆ3»ˆ-ïˆ&‰D‰8a‰#š‰#Ÿ‰)â‰-Š=:Š@xŠ$¹Š0ފ&‹$6‹0[‹7Œ‹ˆÄ‹9MŒ'‡Œ)¯Œٌ=øŒ+6Fb@©'ê4Ž%GŽ#mŽ‘Ž,­Ž"ڎAýŽ6?‚vù2"KTn9Ð"ý* ‘‚K‘%Α2ô‘3'’,[’*ˆ’/³’0ã’2“4G“I|“"Ɠ!é“&”22”e””%œ”6”)ù”0#•+T•%€•NŠ•õ•–!.–[P–1¬–IޖG(—p—I—?חV˜Kn˜Gº˜M™7P™Hˆ™8љ6
š"Aš:dšŸš/»šÞëšÝʛjšœB1V*ˆ³3̝ž`ž$|ž0¡ž*ҞJýž]HŸ³ŠŸÏZ -*¡X¡fv¡EÝ¡#¢&@¢Kg¢+³¢/ߢ2£!B£)d£$Ž£$³£)Ø£?€(B€<k€'š€"Ѐ*󀝊Œ§Чܧ!ó§,š!Bš,dš‘šžšœš(Ú)ìš©©.©2E©x©’©Ÿ©¬©­œ©kªtª1{ª­ªƪ2ݪ#«14«f«2m« « º«"Û«ºþ«†¹¬…@®œÆ¯„°(а=³°ñ° ±#±i+±P•±æ±²!²<²Z²u²"²(³²,ܲ(	³-2³%`³(†³1¯³-á³*Ž*:Ž2eŽ8˜Ž9ÑŽµ%)µ$Oµ1tµе ĵ åµ*¶1¶2N¶¶"¡¶$Ķ$é¶!·!0·R·%n·”·/°· à· ž"ž(;ždž$€ž ¥žÆžäž%¹+(¹$T¹$y¹ž¹œ¹!Ú¹$ü¹!º=º'Xº€ººººغòº»/»L»a»y»1–»È»â»ù»"Œ6ŒTŒ iŒ ŠŒ«ŒÉŒäŒ ýŒœ7œ$Sœ xœ™œ·œ%Õœ+ûœ'Ÿ?ŸWŸ#wŸ›Ÿ»ŸØŸ*õŸ ¿>¿*Z¿5…¿»¿Ú¿!ù¿(À!DÀ"fÀ!‰À)«À&ÕÀ&üÀ#Á$=Á/bÁ/’Á7ÂÁ4úÁ4/ÂBd§ÂÅÂ?ßÂ4Ã)TÃ)~Ã1šÃ.ÚÃ.	Ä<8Ä)uÄ)ŸÄ1ÉÄ.ûÄ.*Å<YÅ)–Å)ÀÅ1êÅ.Æ.KÆ<zÆ$·Æ!ÜÆþÆ)ÇDÇ
[ÇfǂǕÇ
Ç«Ç3²Ç	æÇðÇÈ"È8ÈWÈkȇȓȯÈËÈ-àÈ*É.9ÉVhÉ¿ÉÓÉ@ßɚ Ê»ÊÇÊßÊ^ñÊ9PËpŠË7ûË63Ì?jÌYªÌ>Í4CÍ7xÍ6°Í6çÍRÎAqÎ@³Î@ôÎ(5Ï;^Ï5šÏUÐÏ&ÐRŠÐ4ùÐ..ÑZ]Ñ`žÑ:ÒyTÒ@ÎÒ5ÓiEÓ5¯Ó6åÓ4Ô6QÔUˆÔ0ÞÔVÕ;fÕ8¢Õ%ÛÕIÖ;KÖE‡ÖpÍ֍>×KÌ×JØ9cØ7ØDÕØTÙ:oÙ@ªÙ;ëÙ-'Ú3UÚ.‰Ú.žÚ9çÚ9!Û0[Û/ŒÛ8ŒÛ6õÛ9,ÜCfÜ6ªÜ7áÜ.ÝDHÝ5Ý7ÃÝ4ûÝ60Þ5gÞ5Þ(ÓÞCüÞ8@ß7yß5±ß5çßà
%à3àRà[àAzàNŒàOá\[á;žáHôáA=âNâ)Îâ øâã+ã2ã ?ã7`ã*˜ã*ÃãWîãFä	Nä>Xä6—ä^ÎäE-å:såg®ådæg{æ2ãæJç-aç;ç(Ëç0ôç+%èXQè?ªèDêè</élé'}é(¥éÎéÞé øéê"8ê#[êê)êÇêãê!ë "ë CëFdë
«ë¶ëÆëU×ëb-ì\ìiíìWílí
€íŽí •í¶íÔíôíî"/îRî	eîoî‚î
“î	¡î	«îµîÈî%ãîÌ	ï	Öï àï-ð/ð;>ð"zðoð
ñ(ñ.Eñ
tñJ‚ñjÍñ)8òbòhò4zò)¯ò/ÙòR	ó\ócógó|ó?’ó'Òóúóô+0ô
\ôgô„ô˜ôŽô&Ðô÷ôõ'õDõ\õmõ&€õ&§õ&ÎõõõööO9ö‰ö+öŒöÄöÐöìö4	÷>÷Z÷i÷ ‚÷6£÷Ú÷ç÷ô÷ø3#øWø`øiø‡ø€ø	ÃøÍøàøóøXüø
Uù`ù
wù
…ùù< ù#Ýù
úú	 ú	*ú4úFú	JúTúYú
hú
vú„ú–ú ªú Ëúìú!û)ûEû\ûcû	óûýûPüPbü³üLÈüýJ0ý{ý›ýU·ý
þ"þ%.þTþpþŒþM¡þïþ“ÿ3—ÿ7ËÿDT`!{
ªµœQÂ-:6S5ŠCÀBGYnq€œ)Ñû
	&05
<HGœ
­$»à*åB)S*}š	ŽŸ8Ï'80ipy
ˆ–œ¥(Åî3û/Ge„&ÄÔ"ï-3:(Ilržß˜	§bŒ	,	C	\	r	‹	¢	µ	Ç	à	õ	2
:
Y
k

}
‹
˜
±
Ÿ
Ð
â
ó

"3IZ:x7³ë
(0?NJUJ ›ë‡
 
¬­
7Z,’F¿
&m;U©:ÿï:'*_RE²sø4l<¡TÞE3.y5š;ÞGTb	·Á(Ó$ü!6BJWj(…0®+ß56A
x	†Xhé_Rž²VQšqœ/5<
VEdªÇ"æ!	+KRp¡¹Ò=ì
*A8UzÏÐ| ‘&¯%Ö,ü*)'T.|«·1Œ)î''@-hE–Üò  ’ '° )Ø !"!,B!o!!*­!rØ!K"g"€"‡"–"¢"¶"Ë"ã")#+#&F#'m#•#]Š#$	$0$rL$U¿$%%	7%A%
_%m%y%.%*°%Û%Lø%]E&£&²&Ê&0Î&ÿ'L(%l(’(;®("ê(<
)EJ))0§)3Ø)E*R*Z*f*	j*_t*#Ô*;ø*^4+“+Ÿ+·+Ä+,ß+,4,#R,v,,	‡,V‘,'è,,-
=-H-(^-(‡-°-"Æ-é-.!.;.R.n.‰.€.Â.à.7/8/W/4t/©/Å/Í/Õ/Ý/å/í/õ/ý/0!0+@0l0‡0
€0"¯0Ò0#ï071K1O1<R1717Ç13ÿ1c32F—2Þ2ê2÷2$3=%3%c3<‰37Æ3þ3
4
 4.4D4Z4^4s4†4‹44—4%©4$Ï4#ô45Ã!5>å6,$7Q7"q70”77Å7ý78998…s8†ù8G€9SÈ92:HO:J˜:4ã:;r-;r ;r<M†<Ô<Ø<+á<6
=DD=‰=j©=V>@k>J¬>J÷>B?b?/{?>«?/ê?/@DJ@2@qÂ@=4ArAA›AžAÍAHâA{+Bu§BJC§hDFFF+F'AFiFˆF'žFuÆF$<GraG$ÔGoùGxiH$âH*Ii2I,œI/ÉI,ùI&J)DJ}nJìJ
Ku K–Kx²K6+L$bL$‡LV¬L9MB=MN€MnÏM>NWN@mNU®N.O3O-OO	}O	‡O‘O€O	·OÁOjÚO•EPXÛPW4QBŒQÏQJÐR{S@—SKØSB$T~gT‡æTnUlîUo[V‡ËVdSWpžWZ)X=„X˜ÂXA[Y`YQþYSPZ]€ZP[fS[oº[š*\ÁÅ\Ї]‘^Ž€^3_ʳ_E~`}Ä`tBa{·ag3bl›bqc^zcTÙcK.d]zd\Ød]5eŠ“eUfstfMèfƒ6gEºg4hP5hB†hgÉha1iP“iRäi7jb·jÿk‰l‰€lž.m†ÍmETnTšnFïnF6oG}o;ÅoTpSVpPªplûpWhqWÀqVrMorœrl?sB¬s9ïsI)tBstQ¶tQu8Zub“uZöuSQv=¥v[ãvH?wFˆwYÏwe)x„xlyOy`ÑyO2zL‚z7Ïzb{j{oƒ|Jó|:>}Ay}m»}Z)~‹„~yMŠhØGA€G‰€<р_@n¯=‚ö˂KƒY„Nh„¥·„s]…Sх[%††Tž‡{ó‡{oˆcëˆWO‰Z§‰TŠaWŠc¹Š‡‹G¥‹Fí‹M4Œk‚Œ:îŒC)VmočP4Žf…ŽCìŽD0ŠuHCIJŽØAg‘¢©‘tL’>Á’Š“z‹“—”už”v•ž‹•o*–š–x—a•—K÷—vC˜@º˜cû˜Z_™`ºšªœpƜJ7K‚KΝkžH†žšÏžEjŸ[°Ÿa n Ž¡:›¡YÖ¢N0€B€Á€„¥CŠKVŠp¢Šd§Ix§Q§?šUTšAªš9ìšS&©oz©Hê©A3ª5uª3«ª§ߪ,‡¬Ž®Ю*é®,¯?A¯)¯<«¯è¯*°,°(3°A\°	ž°š°"·°MÚ°)(±R±e± q±쒱²²W–²î²-³A5³!w³P™³ê³\÷³.TŽ,ƒŽ-°ŽÞŽ!ñµ$ž8º	D»BN»Z‘»ì»'þ»&Œ„9ŒPŸŒ9œ1IœE{œ1Áœ3óœ='ŸBeŸ@šŸNéŸC8¿R|¿IÏ¿DÀ]^ÀIŒÀFÁUMÁZ£ÁYþÁZXÂ=³ÂHñÂ<:ÃAwÃ-¹Ã0çÃ0Ä:IÄ3„ÄLžÄ9Å<?ÅE|Å5ÂÅ8øÅ?1Æ-qÆBŸÆ6âÆCÇ6]Ç9”Ç1ÎÇWÈ,XÈE…È1ËÈ.ýÈ=,ÉBjÉA­ÉCïÉ13Ê1eÊ.—Ê<ÆÊ1Ë75Ë7mË0¥Ë-ÖË3Ì:8Ì3sÌ<§ÌAäÌ>&Í6eÍ2œÍHÏÍfÎ5Î/µÎBåÎT(ÏE}Ï3ÃÏC÷ÏE;Ð5Ð2·Ð0êÐ9Ñ1UÑ,‡ÑEŽÑ1úÑ.,Ò=[ÒB™ÒAÜÒ,Ó7KÓIƒÓKÍÓ7Ô4QÔC†ÔGÊÔ5Õ9HÕC‚ÕLÆÕ5Ö2IÖ<|ÖD¹ÖEþÖCD×Eˆ×GÎ×DØQ[Ø0­ØHÞØ\'Ù\„Ù^áÙ[@ÚhœÚlÛ?rÛ-²ÛgàÛUHÜQžÜQðÜSBÝP–Ý]çÝaEÞQ§ÞQùÞSKßPŸß]ðßaNàT°àTáVZáS±á`âdfâBËâ@ã=Oã*ãžãÑãÞã÷ã	ää8äM?ää'šä0Âä!óä?å$Uå)zå€å6ºå$ñå$æ?;æE{æQÁænç‚ç›ç}±ç,/è\é3cé—髪éfV굜êbsëaÖëd8옝ìc6í_šíkúíjfî_Ñî¡1ïÓï~SðsÒðGFñiŽñ`øñ¡YòÊûòwÆóZ>ôX™ô‰òô£|õs öݔöer÷WØ÷Š0ø]×ø`5ù`–ùW÷ù“OúMãú˜1ûhÊûc3üB—üŒÚükgýmÓý±Aþóþƒûÿ‚[X^m·–%[Œu\ŽLëZ8[“UïrEsžX,W…\ÝX:d“øaˆXêTC	{˜	V
Wk
VÃ
^]yY×F1~x_÷aW
a¹
Wsƒ?–ÖÝJó]>hœ{SWÕY-l‡/ô5$$Z?¢_âMBKaÜ	>H‡ONל&QÃT‘j—ü‘”E&zl9çW!TyMÎDka<ÍW
ibÌ-Ù*
2@@G;ÉCCIFLÔ-!LO9œ9Ö9fJ±ÄÝeö~\ €Û –\!ó!"."I"?\")œ"8Æ"?ÿ"3?#+s#Ÿ#³#*Ç#ò#$*$:$M$ c$3„$ž$Ä%5Ý%N&b&g|&Bä&Ÿ''Ç'JÞ'W)((k˜(š)?­)í)ú)A*8U*EŽ*ƒÔ*X+h+l+‡+o¢+G,/Z,*Š,Mµ,-8-O-/o-,Ÿ-5Ì-&. ).5J.+€. ¬. Í.Aî.;0/8l/5¥/Û/!î/i0z0BŠ0Í0Ô0!é041_@1: 1$Û1-25.2Xd2œ2Ì2ß2ø2I3^3n3+u3+¡3>Í34*4'D4l4u4õ4!5(5D5T5ch5?Ì566
;6
I6$T6y6
}6ˆ666¯6Ÿ6Ñ6í6676<7:s78®7?ç7'8é.89'%9xM9rÆ9$9:x^:*×:l;,o;)œ;}Æ;D<b<3x<6¬<$ã<$=k-=™=ê²=Q>]ï>M?lc?Ð?.ã?*@=@D@	W@a@’h@û@%A4A$PA>uADŽATùAZNB©B%ÉB	ïBHùB8BC${C$ CWÅCD.:DiDpDDˆDD–DE!$EFE3bE	–ED EeåE>KF?ŠFÊFÚFíFuG@|GaœGH	5H?HXH	nHxH+ˆH;ŽHðHcýH$aI6†I0œI0îIWJwJ"ŽJB±J(ôJK*K7K<MKŠK&L	?M
IM WMƒxMüMN)#NMN\N&wNžNŒN&ÚNO O=9O#wO›O·OÒOäO ùOP/PIPaPzP’P§P·P!ÈPêP&úP]!QZQ6ÚQ)R;RCRYRoRdvRaÛRù=S7TMTå`TQFUN˜UiçUQV-gV•Vx&WfŸWXX6_Y¢–Y`9ZœšZQX[Eª[~ð[Qo\BÁ\H]HM]`–]„÷]	|^†^?¡^<á^*_I_e_!r_”_E§_Bí_F0`9w`G±`Hù`BaXa‚qa£ôa‘˜bÏ*cQúcLd­kde e6'e(^eZ‡e=âe? f6`fB—f@Úfg-(g5Vg%Œg%²g&Øg'ÿgb'hŠhkŠhoi]‚iààjùÁk6»l6òl[)m?…m9ÅmNÿmNn	Una_nGÁnI	oISoJobèoKpgp†p	ŸpÄ©p=nqB¬qïq4r1Dr)vr/ rCÐržs0³säsÿstt,t Lt#mt)‘t5»t&ñt2uPKu$œurÁu4vMvccvÖÇv žw?x Lxmx8…xŸxÐxàx8ðxB)y7ly†€yŽ+z!àz,{/{ª6{3á|d}Iz}6Ä}Mû}?I~i‰~ló~0`7‘WɁ!€£€¯€	Ā΀ªç€0’pÁ4‚҂낃$ƒGBƒŠƒ4©ƒ#ރ„„„n,„A›„>݄…!)…MK…I™…(ã…4†=A†.†&®†'Ն2ý†50‡5f‡3œ‡(Ї4ù‡U.ˆ.„ˆ1³ˆRåˆ+8‰d‰l‰t‰|‰„‰Œ‰”‰œ‰)€‰ΉFê‰!1Š(SŠ|Š)’Š"ŒŠ7ߊE‹]‹d‹Dk‹?°‹?ð‹>0Œ™oŒc	m€“8£C܍< Ž`]Ž^ŸŽ!6Xt'Š²¶͏	æðôûA?S>“ҐAÈÊX›§ƒ„ÜSéÚÅ>(Ò7ãül+ôČà«F„ŒÀÇîPšœ²c
0Œ«mäi?ŸAއ¡”SØJlOyZ}XNêiKûëŸÁI¥c±΅æ•¯ˆõ¬Ð¡?ˆwDR×"”hÑéöv¶Xª€ŠŸáyñÁ{Žê°xrß8{–en6bž;ŠŽÀõ\Ùr­G:çZ×ĵyE뮄UV`§Õu
q§×*1°I-€«›à†}Þ
¿	st@Rœ¬rEºC&ý}²dU®bÚä—©ÇÓÑ
à÷›€5ȊªLXjŸaxC
¢!©\Ãx]G yŽ~z”¥«3(Ô/)NTP`î`®ÄÙ¯ìd>+&Ï'Ýnð ·Ë3ÑûJ”ow
;^퀊!‡úNTÈþÂK±4hÐ{œlçò‰Ø|æk³îÖ.¯Î…<1\€	Ÿ$¬@DvökÎ40N7"5]pèK5
~sµþ	¬‚©nž8Æ¥m@âi°dâ¶(Œ÷»œ'ùÕ4öÖ‰{p
9ЗÆå	 EùBD™­·ŒQc`×ßA}.>z+^œƒ$}aœûGȈ& MÃ[dJ£?ÒF•,ÁÊ^ÛQjƒCfÔ»KøÁ¡U*=8€çÑ-þp‡’bEðž29˜\)Þ”„6ÀCºØISx«†ï.¡ÙŸk_™Œ¡ò¯Žm‚’šòäܱ|;@YM+†F.^c1Oqðµ˜HO-ÍúàØFr=`¬í—åoŸfºRVYø¥,R"šÒ!8CWۍª•YE‚S‡vË6Åè-!< á>ås[í‰žŠ£*³dÏÿt•вB,ÝÄÃMOÿ=N€²VŠ4$±¹5nŒ†¹ˆ|ŽL“è"ÅÕž¿åÔ^Sé
ô#<÷ŸDœ'$_iŠgÖ¥šµžŸËéœÆ8:r%ñòþLQ ÿú£ßw£#-–ª#gÝúx¶ž¯†c¹Ú9aZO]qÉÉ4vššA|óîê¢e‘ì¿ñQ»Š÷=šk?‹ìzýü˜R…‹6§Üq“H©•‚#y6(Í#±%Þín&]®ö3ôu)óUÊz~˜0mÂãT'®°¢ãª…IÛ	50¢gÜ»ÒÍ.GP[
ÖɃFᛓIH!hÌ·̶HsJïwgWAoálÔä;vóÃùÊ­˜æ7Ï/ÛY“ŽjøÝ>Às,©’™ðBTWufÎ2€l’ôTJ[~&–ÞX[ U°*‘Â_%%—Ì3f§ïø$—hY¹š™êÏç(eï·a„23~ߎPš:g Ž'ž‹‘Š//o‹{–’ÕD¿)ó9j_–€­)pÙ‘%Vb7?*bã<³ü…­Óe™Zu+qëa7/k10Œ@Q:]º9‰ÇzeŽˆœùZÅ:Âɝ2o“ÆõÓfЇwB³ýu³æL\ÌÚP›‚ tŒWì²iƒý<âj Vt|¢‰2K£;M͚Ëü‘pûëMžmtWÿèHÇñ‹âB,h€_G"õÓ=1L
SELinux Distribution fcontext Equivalence 

SELinux Local fcontext Equivalence 
%s changed labels.
%s is already in %s%s is not a domain type%s is not a valid context
%s is not a valid domain%s is not in %s%s must be a directory%s!  Could not get current context for %s, not relabeling tty.
%s!  Could not get new context for %s, not relabeling tty.
%s!  Could not set new context for %s
%s:  Can't load policy and enforcing mode requested:  %s
%s:  Can't load policy:  %s
%s:  Policy is already loaded and initial load requested
'%s' policy modules require existing domains******************** IMPORTANT ***********************
-- Allowed %s [ %s ]-a option can not be used with '%s' domains. Read usage for more details.-d option can not be used with '%s' domains. Read usage for more details.-t option can not be used with '%s' domains. Read usage for more details.-w option can not be used with the --newtype option...600-1024<b>...SELECT TO VIEW DATA...</b><b>Add booleans from the %s policy:</b><b>Add files/directories that %s manages</b><b>Applications</b><b>Deny all processes from ptracing or debugging other processes?</b><b>Disable ability to run unconfined system processes?</b><b>Disable all permissive processes?</b><b>Enter name of application or user role:</b><b>Enter network ports that %s binds on:</b><b>Login Users</b><b>Root Users</b><b>Select additional roles for %s:</b><b>Select common application traits for %s:</b><b>Select domains that %s will administer:</b><b>Select existing role to modify:</b><b>Select network ports that %s connects to:</b><b>Select roles that %s will transition to:</b><b>Select the policy type for the application or user role you want to confine:</b><b>Select the user_roles that will transition to %s:</b><b>Select:</b><b>System Configuration</b><b>System Mode</b><b>TCP Ports</b><b>UDP Ports</b><b>Which directory you will generate the %s policy?</b><operation> File Labeling for <selected domain>. File labels will be created when update is applied.<operation> Network Port for <selected domain>.  Ports will be created when update is applied.<small>
To change from Disabled to Enforcing mode
- Change the system mode from Disabled to Permissive
- Reboot, so that the system can relabel
- Once the system is working as planned
  * Change the system mode to Enforcing</small>
A permissive domain is a process label that allows the process to do what it wants, with SELinux only logging the denials, but not enforcing them.  Usually permissive domains indicate experimental policy, disabling the module could cause SELinux to deny access to a domain, that should be allowed.ActionAddAdd %sAdd BooleanAdd Booleans DialogAdd DirectoryAdd FileAdd File ContextAdd File Equivalency Mapping. Mapping will be created when update is applied.Add File Labeling for %sAdd File Labeling for %s. File labels will be created when update is applied.Add Login MappingAdd Login Mapping. Login Mapping will be created when update is applied.Add Login Mapping. User Mapping will be created when Update is applied.Add Network PortAdd Network Port for %sAdd Network Port for %s.  Ports will be created when update is applied.Add SELinux File EquivalencyAdd SELinux Login MappingAdd SELinux Network PortsAdd SELinux UserAdd SELinux User MappingAdd SELinux User Role. SELinux user roles will be created when update is applied.Add SELinux UsersAdd UserAdd User Roles. SELinux User Roles will be created when Update is applied.Add a fileAdd file Equivalence Mapping.  Mapping will be created when Update is applied.Add file equiv labeling.Add file labeling for %sAdd login mappingAdd new %(TYPE)s file path for '%(DOMAIN)s' domains.Add new File Equivalence definition.Add new Login Mapping definition.Add new SELinux User/Role definition.Add new port definition to which the '%(APP)s' domain is allowed to %(PERM)s.Add ports for %sAdd userAdd/Remove booleans used by the %s domainAddr %s is defined in policy, cannot be deletedAddr %s is not definedAdmin User RoleAdministrator Login User RoleAdvanced <<Advanced >>Advanced Search <<Advanced Search >>AllAll domainsAllow %s to call bindresvport with 0. Binding to port 600-1024Allow ABRT to modify public files used for public file transfer services.Allow Apache to communicate with avahi service via dbusAllow Apache to communicate with sssd service via dbusAllow Apache to execute tmp content.Allow Apache to modify public files used for public file transfer services. Directories/Files must be labeled public_content_rw_t.Allow Apache to query NS recordsAllow Apache to run in stickshift mode, not transition to passengerAllow Apache to run preupgradeAllow Apache to use mod_auth_ntlm_winbindAllow Apache to use mod_auth_pamAllow HTTPD scripts and modules to connect to cobbler over the network.Allow HTTPD scripts and modules to connect to databases over the network.Allow HTTPD scripts and modules to connect to the network using TCP.Allow HTTPD scripts and modules to server cobbler files.Allow HTTPD to connect to port 80 for graceful shutdownAllow HTTPD to run SSI executables in the same domain as system CGI scripts.Allow Puppet client to manage all file types.Allow Puppet master to use connect to MySQL and PostgreSQL databaseAllow Redis to run redis-sentinal notification scripts.Allow Zabbix to run su/sudo.Allow ZoneMinder to modify public files used for public file transfer services.Allow ZoneMinder to run su/sudo.Allow a user to login as an unconfined domainAllow all daemons the ability to read/write terminalsAllow all daemons to use tcp wrappers.Allow all daemons to write corefiles to /Allow all domains to execute in fips_modeAllow all domains to have the kernel load modulesAllow all domains to use other domains file descriptorsAllow all domains write to kmsg_device, while kernel is executed with systemd.log_target=kmsg parameter.Allow all unconfined executables to use libraries requiring text relocation that are not labeled textrel_shlib_tAllow antivirus programs to read non security files on a systemAllow any files/directories to be exported read/only via NFS.Allow any files/directories to be exported read/write via NFS.Allow any process to mmap any file on system with attribute file_type.Allow apache scripts to write to public content, directories/files must be labeled public_rw_content_t.Allow auditadm to exec contentAllow cluster administrative cluster domains memcheck-amd64- to use executable memoryAllow cluster administrative domains to connect to the network using TCP.Allow cluster administrative domains to manage all files on a system.Allow confined applications to run with kerberos.Allow confined applications to use nscd shared memory.Allow confined users the ability to execute the ping and traceroute commands.Allow confined virtual guests to interact with rawip socketsAllow confined virtual guests to interact with the sanlockAllow confined virtual guests to interact with the xserverAllow confined virtual guests to manage cifs filesAllow confined virtual guests to manage nfs filesAllow confined virtual guests to read fuse filesAllow confined virtual guests to use executable memory and executable stackAllow confined virtual guests to use glusterdAllow confined virtual guests to use serial/parallel communication portsAllow confined virtual guests to use usb devicesAllow confined web browsers to read home directory contentAllow conman to manage nfs filesAllow cups execmem/execstackAllow database admins to execute DML statementAllow dbadm to exec contentAllow dhcpc client applications to execute iptables commandsAllow ftpd to use ntfs/fusefs volumes.Allow ganesha to read/write fuse filesAllow glance domain to manage fuse filesAllow glance domain to use executable memory and executable stackAllow glusterd_t domain to use executable memoryAllow glusterfsd to modify public files used for public file transfer services.  Files/Directories must be labeled public_content_rw_t.Allow glusterfsd to share any file/directory read only.Allow glusterfsd to share any file/directory read/write.Allow gpg web domain to modify public files used for public file transfer services.Allow gssd to list tmp directories and read the kerberos credential cache.Allow guest to exec contentAllow http daemon to check spamAllow http daemon to connect to mythtvAllow http daemon to connect to zabbixAllow http daemon to send mailAllow httpd cgi supportAllow httpd daemon to change its resource limitsAllow httpd processes to manage IPA contentAllow httpd processes to run IPA helper.Allow httpd scripts and modules execmem/execstackAllow httpd to access FUSE file systemsAllow httpd to access cifs file systemsAllow httpd to access nfs file systemsAllow httpd to access openstack portsAllow httpd to act as a FTP client connecting to the ftp port and ephemeral portsAllow httpd to act as a FTP server by listening on the ftp port.Allow httpd to act as a relayAllow httpd to connect to  saslAllow httpd to connect to memcache serverAllow httpd to connect to the ldap portAllow httpd to read home directoriesAllow httpd to read user contentAllow httpd to run gpgAllow httpd to use built in scripting (usually php)Allow ksmtuned to use cifs/Samba file systemsAllow ksmtuned to use nfs file systemsAllow logadm to exec contentAllow logging in and using the system from /dev/console.Allow logrotate to manage nfs filesAllow logrotate to read logs insideAllow mailman to access FUSE file systemsAllow mock to read files in home directories.Allow mozilla plugin domain to bind unreserved tcp/udp ports.Allow mozilla plugin domain to connect to the network using TCP.Allow mozilla plugin to support GPS.Allow mozilla plugin to support spice protocols.Allow mozilla plugin to use Bluejeans.Allow mysqld to connect to all portsAllow nagios run in conjunction with PNP4Nagios.Allow nagios/nrpe to call sudo from NRPE utils scripts.Allow nfs servers to modify public files used for public file transfer services.  Files/Directories must be labeled public_content_rw_t.Allow openshift to access nfs file systems without labelsAllow openvpn to run unconfined scriptsAllow pcp to bind to all unreserved_portsAllow pcp to read generic logsAllow piranha-lvs domain to connect to the network using TCP.Allow polipo to connect to all ports > 1023Allow postfix_local domain full write access to mail_spool directoriesAllow postgresql to use ssh and rsync for point-in-time recoveryAllow pppd to be run for a regular userAllow pppd to load kernel modules for certain modemsAllow qemu-ga to manage qemu-ga date.Allow qemu-ga to read qemu-ga date.Allow racoon to read shadowAllow regular users direct dri device accessAllow rpcd_t  to manage fuse filesAllow rsync server to manage all files/directories on the system.Allow rsync to export any files/directories read only.Allow rsync to modify public files used for public file transfer services.  Files/Directories must be labeled public_content_rw_t.Allow rsync to run as a clientAllow s-c-kdump to run bootloader in bootloader_t.Allow samba to act as a portmapperAllow samba to act as the domain controller, add users, groups and change passwords.Allow samba to create new home directories (e.g. via PAM)Allow samba to export NFS volumes.Allow samba to export ntfs/fusefs volumes.Allow samba to modify public files used for public file transfer services.  Files/Directories must be labeled public_content_rw_t.Allow samba to run unconfined scriptsAllow samba to share any file/directory read only.Allow samba to share any file/directory read/write.Allow samba to share users home directories.Allow sandbox containers manage fuse filesAllow sandbox containers to send audit messagesAllow sandbox containers to use all capabilitiesAllow sandbox containers to use mknod system callsAllow sandbox containers to use netlink system callsAllow sandbox containers to use sys_admin system calls, for example mountAllow sanlock to manage cifs filesAllow sanlock to manage nfs filesAllow sanlock to read/write fuse filesAllow sanlock to read/write user home directories.Allow sasl to read shadowAllow secadm to exec contentAllow sge to access nfs file systems.Allow sge to connect to the network using any TCP portAllow smbd to load libgfapi from gluster.Allow spamd to read/write user home directories.Allow spamd_update to connect to all ports.Allow ssh logins as sysadm_r:sysadm_tAllow ssh with chroot env to read and write files in the user home directoriesAllow staff to exec contentAllow sysadm to exec contentAllow syslogd daemon to send mailAllow syslogd the ability to call nagios plugins. It is turned on by omprog rsyslog plugin.Allow syslogd the ability to read/write terminalsAllow system cron jobs to relabel filesystem for restoring file contexts.Allow system cronjob to be executed on on NFS, CIFS or FUSE filesystem.Allow system to run with NISAllow tftp to modify public files used for public file transfer services.Allow tftp to read and write files in the user home directoriesAllow the Irssi IRC Client to connect to any port, and to bind to any unreserved port.Allow the Telepathy connection managers to connect to any generic TCP port.Allow the Telepathy connection managers to connect to any network port.Allow the graphical login program to create files in HOME dirs as xdm_home_t.Allow the graphical login program to execute bootloaderAllow the graphical login program to login directly as sysadm_r:sysadm_tAllow the mount commands to mount any directory or file.Allow tomcat to connect to databases over the network.Allow tomcat to read rpm database.Allow tomcat to use executable memory and executable stackAllow tor to act as a relayAllow transmit client label to foreign databaseAllow unconfined executables to make their heap memory executable.  Doing this is a really bad idea. Probably indicates a badly coded executable, but could indicate an attack. This executable should be reported in bugzillaAllow unconfined executables to make their stack executable.  This should never, ever be necessary. Probably indicates a badly coded executable, but could indicate an attack. This executable should be reported in bugzillaAllow unconfined users to transition to the Mozilla plugin domain when running xulrunner plugin-container.Allow unprivileged user to create and transition to svirt domains.Allow unprivileged users to execute DDL statementAllow user  to use ssh chroot environment.Allow user music sharingAllow user spamassassin clients to use the network.Allow user to exec contentAllow user to r/w files on filesystems that do not have extended attributes (FAT, CDROM, FLOPPY)Allow users to connect to PostgreSQLAllow users to connect to the local mysql serverAllow users to login using a radius serverAllow users to login using a yubikey OTP server or challenge response modeAllow users to resolve user passwd entries directly from ldap rather then using a sssd serverAllow users to run TCP servers (bind to ports and accept connection from the same domain and outside users)  disabling this forces FTP passive mode and may change other protocols.Allow users to run UDP servers (bind to ports and accept connection from the same domain and outside users)  disabling this may break avahi discovering services on the network and other udp related services.Allow virtual processes to run as userdomainsAllow xen to manage nfs filesAllow xend to run blktapctrl/tapdisk. Not required if using dedicated logical volumes for disk images.Allow xend to run qemu-dm. Not required if using paravirt and no vfb.Allow xguest to exec contentAllow xguest to use blue tooth devicesAllow xguest users to configure Network Manager and connect to apache portsAllow xguest users to mount removable mediaAllow zarafa domains to setrlimit/sys_resource.Allow zebra daemon to write it configuration filesAllows %s to bind to any udp portAllows %s to bind to any udp ports > 1024Allows %s to connect to any tcp portAllows %s to connect to any udp portAllows XServer to execute writable memoryAllows clients to write to the X server shared memory segments.Allows xdm_t to bind on vnc_port_t(5910)Alternate SELinux policy, defaults to /sys/fs/selinux/policyAlternate root directory, defaults to /Alternative root needs to be setupAn permissive domain is a process label that allows the process to do what it wants, with SELinux only logging the denials, but not enforcing them.  Usually permissive domains indicate experimental policy, disabling the module could cause SELinux to deny access to a domain, that should be allowed.An unconfined domain is a process label that allows the process to do what it wants, without SELinux interfering.  Applications started at boot by the init system that SELinux do not have defined SELinux policy will run as unconfined if this module is enabled.  Disabling it means all daemons will now be confined.  To disable the unconfined_t user you must first remove unconfined_t from the users/login screens.Analyzing Policy...ApplicationApplication File TypesApplication Transitions From '%s'Application Transitions From 'select domain'Application Transitions Into '%s'Application Transitions Into 'select domain'ApplicationsApplications - Advanced SearchApplyAre you sure you want to delete %s '%s'?Bad format %(BOOLNAME)s: Record %(VALUE)sBooleanBoolean
EnabledBoolean %s Allow RulesBoolean %s is defined in policy, cannot be deletedBoolean %s is not definedBoolean NameBoolean nameBoolean section.Boolean to determine whether the system permits loading policy, setting enforcing mode, and changing boolean values.  Set this to true and you have to reboot to set it back.BooleansBrowseBrowse to select the file/directory for labeling.Builtin Permissive TypesCalling Process DomainCan not combine +/- with other types of categoriesCan not have multiple sensitivitiesCan not modify sensitivity levels using '+' on %sCancelCannot find your entry in the shadow passwd file.
Cannot read policy store.Change process mode to enforcingChange process mode to permissive.Changing the policy type will cause a relabel of the entire file system on the next boot. Relabeling takes a long time depending on the size of the file system.  Do you wish to continue?Changing to SELinux disabled requires a reboot.  It is not recommended.  If you later decide to turn SELinux back on, the system will be required to relabel.  If you just want to see if SELinux is causing a problem on your system, you can go to permissive mode which will only log errors and not enforce SELinux policy.  Permissive mode does not require a reboot    Do you wish to continue?Changing to SELinux disabled requires a reboot.  It is not recommended.  If you later decide to turn SELinux back on, the system will be required to relabel.  If you just want to see if SELinux is causing a problem on your system, you can go to permissive mode which will only log errors and not enforce SELinux policy.  Permissive mode does not require a reboot.  Do you wish to continue?Changing to SELinux enabled will cause a relabel of the entire file system on the next boot. Relabeling takes a long time depending on the size of the file system.  Do you wish to continue?ClassCommand required for this type of policyCommit all changes in your current transaction to the server.Configue SELinuxConfined Root Administrator RoleContextControl the ability to mmap a low area of the address space, as configured by /proc/sys/vm/mmap_min_addr.Copyright (c)2006 Red Hat, Inc.
Copyright (c) 2006 Dan Walsh <dwalsh@redhat.com>Could not add SELinux user %sCould not add addr %sCould not add file context for %sCould not add ibendport %s/%sCould not add ibpkey %s/%sCould not add interface %sCould not add login mapping for %sCould not add port %(PROTOCOL)s/%(PORT)sCould not add prefix %(PREFIX)s for %(ROLE)sCould not add role %(ROLE)s for %(NAME)sCould not check if SELinux user %s is definedCould not check if addr %s is definedCould not check if boolean %s is definedCould not check if file context for %s is definedCould not check if ibendport %s/%s is definedCould not check if ibpkey %s/%s is definedCould not check if interface %s is definedCould not check if login mapping for %s is definedCould not check if port %(PROTOCOL)s/%(PORT)s is definedCould not check if port @%(PROTOCOL)s/%(PORT)s is definedCould not close descriptors.
Could not commit semanage transactionCould not create SELinux user for %sCould not create a key for %(PROTOTYPE)s/%(PORT)sCould not create a key for %sCould not create a key for %s/%dCould not create a key for %s/%sCould not create a key for ibendport %s/%sCould not create addr for %sCould not create context for %(PROTOCOL)s/%(PORT)sCould not create context for %sCould not create context for %s/%sCould not create file context for %sCould not create ibendport for %s/%sCould not create ibpkey for %s/%sCould not create interface for %sCould not create key for %sCould not create login mapping for %sCould not create module keyCould not create port for %(PROTOCOL)s/%(PORT)sCould not create semanage handleCould not delete SELinux user %sCould not delete addr %sCould not delete all interface  mappingsCould not delete boolean %sCould not delete file context for %sCould not delete ibendport %s/%sCould not delete ibpkey %s/%sCould not delete interface %sCould not delete login mapping for %sCould not delete port %(PROTOCOL)s/%(PORT)sCould not delete the file context %sCould not delete the ibendport %s/%dCould not delete the ibpkey %sCould not delete the port %sCould not deleteall node mappingsCould not determine enforcing mode.
Could not disable module %sCould not enable module %sCould not establish semanage connectionCould not extract key for %sCould not get module enabledCould not get module lang_extCould not get module nameCould not get module priorityCould not list SELinux modulesCould not list SELinux usersCould not list addrsCould not list booleansCould not list file contextsCould not list file contexts for home directoriesCould not list ibendportsCould not list ibpkeysCould not list interfacesCould not list local file contextsCould not list login mappingsCould not list portsCould not list roles for user %sCould not list the file contextsCould not list the ibendportsCould not list the ibpkeysCould not list the portsCould not modify SELinux user %sCould not modify addr %sCould not modify boolean %sCould not modify file context for %sCould not modify ibendport %s/%sCould not modify ibpkey %s/%sCould not modify interface %sCould not modify login mapping for %sCould not modify port %(PROTOCOL)s/%(PORT)sCould not open file %s
Could not query addr %sCould not query file context %sCould not query file context for %sCould not query ibendport %s/%sCould not query ibpkey %s/%sCould not query interface %sCould not query port %(PROTOCOL)s/%(PORT)sCould not query seuser for %sCould not query user for %sCould not remove module %s (remove failed)Could not remove permissive domain %s (remove failed)Could not set MLS level for %sCould not set MLS range for %sCould not set SELinux user for %sCould not set active value of boolean %sCould not set addr context for %sCould not set exec context to %s.
Could not set file context for %sCould not set ibendport context for %s/%sCould not set ibpkey context for %s/%sCould not set interface context for %sCould not set mask for %sCould not set message context for %sCould not set mls fields in addr context for %sCould not set mls fields in file context for %sCould not set mls fields in ibendport context for %s/%sCould not set mls fields in ibpkey context for %s/%sCould not set mls fields in interface context for %sCould not set mls fields in port context for %(PROTOCOL)s/%(PORT)sCould not set module key nameCould not set name for %sCould not set permissive domain %s (module installation failed)Could not set port context for %(PROTOCOL)s/%(PORT)sCould not set role in addr context for %sCould not set role in file context for %sCould not set role in ibendport context for %s/%sCould not set role in ibpkey context for %s/%sCould not set role in interface context for %sCould not set role in port context for %(PROTOCOL)s/%(PORT)sCould not set type in addr context for %sCould not set type in file context for %sCould not set type in ibendport context for %s/%sCould not set type in ibpkey context for %s/%sCould not set type in interface context for %sCould not set type in port context for %(PROTOCOL)s/%(PORT)sCould not set user in addr context for %sCould not set user in file context for %sCould not set user in ibendport context for %s/%sCould not set user in ibpkey context for %s/%sCould not set user in interface context for %sCould not set user in port context for %(PROTOCOL)s/%(PORT)sCould not start semanage transactionCould not test MLS enabled statusCouldn't get default type.
Create/Manipulate temporary files in /tmpCurrent Enforcing ModeCustomizedCustomized Permissive TypesDBUS System DaemonDefaultDefault LevelDeleteDelete %(TYPE)s file paths for '%(DOMAIN)s' domain.Delete %sDelete File ContextDelete Modified File LabelingDelete Modified PortsDelete Modified Users Mapping.Delete Network PortDelete SELinux User MappingDelete UserDelete file equiv labeling.Delete file labeling for %sDelete login mappingDelete modified File Equivalence definitions.Delete modified Login Mapping definitions.Delete modified SELinux User/Role definitions.Delete modified port definitions to which the '%(APP)s' domain is allowed to %(PERM)s.Delete ports for %sDelete userDeny any process from ptracing or debugging any other processes.Deny user domains applications to map a memory region as both executable and writable, this is dangerous and the executable should be reported in bugzillaDescriptionDesktop Login User RoleDestination ClassDetermine whether ABRT can run in the abrt_handle_event_t domain to handle ABRT event scripts.Determine whether Bind can bind tcp socket to http ports.Determine whether Bind can write to master zone files. Generally this is used for dynamic DNS or zone transfers.Determine whether Cobbler can access cifs file systems.Determine whether Cobbler can access nfs file systems.Determine whether Cobbler can connect to the network using TCP.Determine whether Cobbler can modify public files used for public file transfer services.Determine whether Condor can connect to the network using TCP.Determine whether DHCP daemon can use LDAP backends.Determine whether Git CGI can access cifs file systems.Determine whether Git CGI can access nfs file systems.Determine whether Git CGI can search home directories.Determine whether Git session daemon can bind TCP sockets to all unreserved ports.Determine whether Git system daemon can access cifs file systems.Determine whether Git system daemon can access nfs file systems.Determine whether Git system daemon can search home directories.Determine whether Gitosis can send mail.Determine whether Nagios, NRPE can access nfs file systems.Determine whether Polipo can access nfs file systems.Determine whether Polipo session daemon can bind tcp sockets to all unreserved ports.Determine whether abrt-handle-upload can modify public files used for public file transfer services in /var/spool/abrt-upload/.Determine whether attempts by wine to mmap low regions should be silently blocked.Determine whether awstats can purge httpd log files.Determine whether boinc can execmem/execstack.Determine whether calling user domains can execute Git daemon in the git_session_t domain.Determine whether calling user domains can execute Polipo daemon in the polipo_session_t domain.Determine whether can antivirus programs use JIT compiler.Determine whether cdrecord can read various content. nfs, samba, removable devices, user temp and untrusted content filesDetermine whether collectd can connect to the network using TCP.Determine whether conman can connect to all TCP portsDetermine whether crond can execute jobs in the user domain as opposed to the the generic cronjob domain.Determine whether cvs can read shadow password files.Determine whether dbadm can manage generic user files.Determine whether dbadm can read generic user files.Determine whether docker can connect to all TCP ports.Determine whether entropyd can use audio devices as the source for the entropy feeds.Determine whether exim can connect to databases.Determine whether exim can create, read, write, and delete generic user content files.Determine whether exim can read generic user content files.Determine whether fenced can connect to the TCP network.Determine whether fenced can use ssh.Determine whether ftpd can bind to all unreserved ports for passive mode.Determine whether ftpd can connect to all unreserved ports.Determine whether ftpd can connect to databases over the TCP network.Determine whether ftpd can login to local users and can read and write all files on the system, governed by DAC.Determine whether ftpd can modify public files used for public file transfer services. Directories/Files must be labeled public_content_rw_t.Determine whether ftpd can use CIFS used for public file transfer services.Determine whether ftpd can use NFS used for public file transfer services.Determine whether glance-api can connect to all TCP portsDetermine whether haproxy can connect to all TCP ports.Determine whether icecast can listen on and connect to any TCP port.Determine whether irc clients can listen on and connect to any unreserved TCP ports.Determine whether keepalived can connect to all TCP ports.Determine whether logwatch can connect to mail over the network.Determine whether lsmd_plugin can connect to all TCP ports.Determine whether mcelog can execute scripts.Determine whether mcelog can use all the user ttys.Determine whether mcelog supports client mode.Determine whether mcelog supports server mode.Determine whether minidlna can read generic user content.Determine whether mpd can traverse user home directories.Determine whether mpd can use cifs file systems.Determine whether mpd can use nfs file systems.Determine whether mplayer can make its stack executable.Determine whether neutron can connect to all TCP portsDetermine whether openvpn can connect to the TCP network.Determine whether openvpn can read generic user home content files.Determine whether polipo can access cifs file systems.Determine whether privoxy can connect to all tcp ports.Determine whether radius can use JIT compiler.Determine whether smartmon can support devices on 3ware controllers.Determine whether squid can connect to all TCP ports.Determine whether squid can run as a transparent proxy.Determine whether swift can connect to all TCP portsDetermine whether tmpreaper can use cifs file systems.Determine whether tmpreaper can use nfs file systems.Determine whether tmpreaper can use samba_share filesDetermine whether to support lpd server.Determine whether tor can bind tcp sockets to all unreserved ports.Determine whether varnishd can use the full TCP network.Determine whether webadm can manage generic user files.Determine whether webadm can read generic user files.Determine whether zabbix can connect to all TCP portsDisableDisable AuditDisable kernel module loading.DisabledDisabled
Permissive
Enforcing
Display applications that can transition into or out of the '%s'.Display applications that can transition into or out of the 'selected domain'.Display boolean information that can be used to modify the policy for the '%s'.Display boolean information that can be used to modify the policy for the 'selected domain'.Display file type information that can be used by the '%s'.Display file type information that can be used by the 'selected domain'.Display network ports to which the '%s' can connect or listen to.Display network ports to which the 'selected domain' can connect or listen to.Domain name(s) of man pages to be createdDontaudit Apache to search dirs.Edit Network PortEnableEnable AuditEnable cluster mode for daemons.Enable extra rules in the cron domain to support fcron.Enable polyinstantiated directory support.Enable reading of urandom for all domains.Enable/Disable additional audit rules, that are normally not reported in the log files.EnabledEnforcingEnter Default Level for SELinux User to login with. Default s0Enter MLS/MCS Range for this SELinux User.
s0-s0:c1023Enter MLS/MCS Range for this login User.  Defaults to the range for the Selected SELinux User.Enter SELinux role(s) to which the administror domain will transitionEnter SELinux user(s) which will transition to this domainEnter a comma separated list of tcp ports or ranges of ports that %s connects to. Example: 612, 650-660Enter a comma separated list of udp ports or ranges of ports that %s binds to. Example: 612, 650-660Enter a comma separated list of udp ports or ranges of ports that %s connects to. Example: 612, 650-660Enter complete path for executable to be confined.Enter complete path to init script used to start the confined application.Enter domain type which you will be extendingEnter domain(s) which this confined admin will administrateEnter interface names, you wish to queryEnter the MLS Label to assign to this file path.Enter the MLS Label to assign to this port.Enter the login user name of the user to which you wish to add SELinux User confinement.Enter the path to which you want to setup an equivalence label.Enter the port number or range to which you want to add a port type.Enter unique name for the confined application or user role.Equivalence PathEquivalence class for %s already existsEquivalence class for %s does not existsEquivalence: %sError allocating memory.
Error allocating shell's argv0.
Error changing uid, aborting.
Error connecting to audit system.
Error resetting KEEPCAPS, aborting
Error sending audit message.
Error!  Could not clear O_NONBLOCK on %s
Error!  Could not open %s.
Error!  Shell is not valid.
Error: multiple levels specified
Error: multiple roles specified
Error: multiple types specified
Error: you are not allowed to change levels on a non secure terminal 
ExecutableExecutable FileExecutable FilesExecutables which will transition to a different domain, when the '%s' executes them.Executables which will transition to a different domain, when the 'selected domain' executes them.Executables which will transition to the '%s', when executing a selected domains entrypoint.Executables which will transition to the 'selected domain', when executing a selected domains entrypoint.Existing Domain TypeExisting User RolesExisting_UserExportExport system settings to a fileFailed to close tty properly
Failed to drop capabilities %m
Failed to read %s policy fileFailed to send audit messageFailed to transition to namespace
File
SpecificationFile
TypeFile Contexts fileFile EquivalenceFile LabelingFile NameFile PathFile SpecificationFile Transitions From '%s'File Transitions From 'select domain'File Transitions define what happens when the current domain creates the content of a particular class in a directory of the destination type. Optionally a file name could be specified for the transition.File TypeFile Types defined for the '%s'.File Types defined for the 'selected domain'.File class: %sFile context for %s is defined in policy, cannot be deletedFile context for %s is not definedFile equivalence cause the system to label content under the new path as if it were under the equivalence path.File path : %sFile path used to enter the '%s' domain.File path used to enter the 'selected domain'.File path: %sFile spec %(TARGET)s conflicts with equivalency rule '%(SOURCE)s %(DEST)s'File spec %(TARGET)s conflicts with equivalency rule '%(SOURCE)s %(DEST)s'; Try adding '%(DEST1)s' insteadFile specification can not include spacesFilesFiles EquivalenceFiles by '%s' will transitions to a different label.Files to which the '%s' domain can write.Files to which the 'selected domain' can write.Files/Directories which the %s "manages". Pid Files, Log Files, /var/lib Files ...FilterGPLGenerate '%s' policyGenerate '%s' policy Generate HTML man pages structure for selected SELinux man pageGenerate SELinux Policy module templateGenerate SELinux man pagesGenerate new policy moduleGraphical User Interface for SELinux PolicyGroup ViewHelp: Application Types PageHelp: Booleans PageHelp: Executable Files PageHelp: File Equivalence PageHelp: Inbound Network Connections PageHelp: Lockdown PageHelp: Login PageHelp: Outbound Network Connections PageHelp: SELinux User PageHelp: Start PageHelp: Systems PageHelp: Transition application file PageHelp: Transition from application PageHelp: Transition into application PageHelp: Writable Files PageIB Device NameIB device name is requiredIf-Then-Else rules written in policy that can
allow alternative access control.ImportImport system settings from another machineInboundInit scriptInteracts with the terminalInterface %s does not exist.Interface %s is defined in policy, cannot be deletedInterface %s is not definedInterface fileInternet Services DaemonInternet Services Daemon (inetd)Internet Services Daemon are daemons started by xinetdInvalid PkeyInvalid PortInvalid Port NumberInvalid file specificationInvalid priority %d (needs to be between 1 and 999)LabelingLanguageLinux Group %s does not existLinux User %s does not existList SELinux Policy interfacesList ViewLoad Policy ModuleLoad policy moduleLockdownLockdown the SELinux System.
This screen can be used to turn up the SELinux Protections.Login
NameLogin '%s' is requiredLogin MappingLogin NameLogin Name : %sLogin mapping for %s is defined in policy, cannot be deletedLogin mapping for %s is not definedLogin nameLoss of data DialogMCS LevelMCS RangeMISSING FILE PATHMLSMLS RangeMLS/MLS/
MCS RangeMLS/MCS
LevelMLS/MCS RangeMLS/MCS Range: %sMake Path RecursiveManage the SELinux configurationMinimal Terminal Login User RoleMinimal Terminal User RoleMinimal X Windows Login User RoleMinimal X Windows User RoleMislabeled files existModifyModify %(TYPE)s file path for '%(DOMAIN)s' domain. Only bolded items in the list can be selected, this indicates they were modified previously.Modify %sModify File ContextModify File Equivalency Mapping. Mapping will be created when update is applied.Modify File Labeling for %s. File labels will be created when update is applied.Modify Login MappingModify Login Mapping. Login Mapping will be modified when Update is applied.Modify Network Port for %sModify Network Port for %s.  Ports will be created when update is applied.Modify SELinux File EquivalencyModify SELinux User MappingModify SELinux User Role. SELinux user roles will be modified when update is applied.Modify SELinux UsersModify UserModify an existing login user record.Modify file equiv labeling.Modify file labeling for %sModify login mappingModify port definitions to which the '%(APP)s' domain is allowed to %(PERM)s.Modify ports for %sModify selected modified File Equivalence definitions. Only bolded items in the list can be selected, this indicates they were modified previously.Modify selected modified Login Mapping definitions.Modify selected modified SELinux User/Role definitions.Modify userModule %s already loaded in current policy.
Do you want to continue?Module NameModule does not exists %s Module information for a new typeMore DetailsMore TypesMore...NameName must be alpha numberic with no spaces. Consider using option "-n MODULENAME"NetworkNetwork
Bind tabNetwork PortNetwork Port DefinitionsNetwork Ports to which the '%s' is allowed to connect.Network Ports to which the '%s' is allowed to listen.Network Ports to which the 'selected domain' is allowed to connect.Network Ports to which the 'selected domain' is allowed to listen.Network ports: %sNetwork protocol: %sNoNo SELinux Policy installedNo context in file %s
Node Address is requiredNot yet implementedOnly Daemon apps can use an init script..Options Error %s Out of memory!
OutboundPassword:PathPath  PermissivePermit to prosody to bind apache port. Need to be activated to use BOSH.Pkey NumberPolicy DirectoryPolicy ModulePolicy types which require a commandPortPort %(PROTOCOL)s/%(PORT)s already definedPort %(PROTOCOL)s/%(PORT)s is defined in policy, cannot be deletedPort %(PROTOCOL)s/%(PORT)s is not definedPort @%(PROTOCOL)s/%(PORT)s is not definedPort NumberPort TypePort is requiredPort number "%s" is not valid.  0 < PORT_NUMBER < 65536 Port number must be between 1 and 65536Ports must be numbers or ranges of numbers from 1 to %d PrefixPriorityProcess DomainProcess TypesProtoProtocolProtocol udp or tcp is requiredQuery SELinux policy network informationRed Hat 2007Relabel all files back to system defaults on rebootRelabel on next reboot.Remove loadable policy moduleRequires at least one categoryRequires prefix or rolesRequires prefix, roles, level or rangeRequires setypeRequires setype or serangeRequires setype, serange or seuserRequires seuser or serangeRetryRevertRevert ChangesRevert boolean setting to system defaultRevert button will launch a dialog window which allows you to revert changes within the current transaction.Review the updates you have made before committing them to the system.  To reset an item, uncheck the checkbox.  All items checked will be updated in the system when you select update.RoleRoles: %sRoot Admin User RoleRun restorecon on %(PATH)s to change its type from %(CUR_CONTEXT)s to the default %(DEF_CONTEXT)s?SELinux
UserSELinux AdministrationSELinux Application TypeSELinux ConfigurationSELinux Destination TypeSELinux Directory TypeSELinux File LabelSELinux File TypeSELinux IB End Port TypeSELinux IB Pkey TypeSELinux InterfaceSELinux MLS Label you wish to assign to this path.SELinux Policy Generation ToolSELinux Port
TypeSELinux Port TypeSELinux RolesSELinux TypeSELinux Type is requiredSELinux UserSELinux User : %sSELinux User NameSELinux User: %sSELinux UsernameSELinux UsersSELinux booleanSELinux fcontextSELinux file type: %sSELinux name: %sSELinux node type is requiredSELinux policy is not managed or store cannot be accessed.SELinux user %s is defined in policy, cannot be deletedSELinux user %s is not definedSELinux user '%s' is requiredSandboxSave to UpdateSave to updateSelectSelect <b>tcp</b> if the port type should be assigned to tcp port numbers.Select <b>udp</b> if the port type should be assigned to udp port numbers.Select Make Path Recursive if you want to apply this label to all children of the specified directory path. objects under the directory to have this label.Select Management ObjectSelect PortsSelect Root Administrator User Role, if this user will be used to administer the machine while running as root.  This user will not be able to login to the system directly.Select applications domains that %s will transition to.Select directory to generate policy files inSelect directory(s) that the confined application owns and writes intoSelect domainSelect executable file to be confined.Select file equivalence labeling to delete. File equivalence labeling will be deleted when update is applied.Select file labeling to delete. File labeling will be deleted when update is applied.Select file(s) that confined application creates or writesSelect if you wish to relabel then entire file system on next reboot.  Relabeling can take a very long time, depending on the size of the system.  If you are changing policy types or going from disabled to enforcing, a relabel is required.Select init script file to be confined.Select login user mapping to delete. Login user mapping will be deleted when update is applied.Select ports to delete. Ports will be deleted when update is applied.Select the SELinux User to assign to this login user.  Login users by default get assigned by the __default__ user.Select the SELinux file type to assign to this path.Select the domains that you would like this user administer.Select the file class to which this label will be applied.  Defaults to all classes.Select the port type you want to assign to the specified port number.Select the system mode for the current sessionSelect the system mode when the system first boots upSelect the user roles that will transiton to the %s domain.Select the user roles that will transiton to this applications domains.Select users mapping to delete.Users mapping will be deleted when update is applied.Select...Selinux
File TypeSemanage transaction already in progressSemanage transaction not in progressSends audit messagesSends emailServiceSetup ScriptShow Modified OnlyShow mislabeled files onlyShow ports defined for this SELinux typeSorry, -l may be used with SELinux MLS support.
Sorry, newrole failed to drop capabilities
Sorry, newrole may be used only on a SELinux kernel.
Sorry, run_init may be used only on a SELinux kernel.
Source DomainSpec fileSpecify a new SELinux user name.  By convention SELinux User names usually end in an _u.Specify the MLS Range for this user to login in with.  Defaults to the selected SELinux Users MLS Range.Specify the default level that you would like this SELinux user to login with.  Defaults to s0.Specify the mapping between the new path and the equivalence path.  Everything under this new path will be labeled as if they were under the equivalence path.Specify the path using regular expressions that you would like to modify the labeling.Standard Init DaemonStandard Init Daemon are daemons started on boot via init scripts.  Usually requires a script in /etc/rc.d/init.dStateStatusSubnet Prefix is requiredSubnet_PrefixSubstitute %s is not valid. Substitute is not allowed to end with '/'Support NFS home directoriesSupport SAMBA home directoriesSupport X userspace object managerSupport ecryptfs home directoriesSupport fusefs home directoriesSystemSystem Default Enforcing ModeSystem Default Policy Type: System Policy Type:System Status: DisabledSystem Status: EnforcingSystem Status: PermissiveTarget %s is not valid. Target is not allowed to end with '/'Target DomainThe entry '%s' is not a valid path.  Paths must begin with a '/'.The entry that was entered is incorrect.  Please try again in the ex:/.../... format.The sepolgen python module is required to setup permissive domains.
In some distributions it is included in the policycoreutils-devel patckage.
# yum install policycoreutils-devel
Or similar for your distro.This user can login to a machine via X or terminal.  By default this user will have no setuid, no networking, no sudo, no suThis user will login to a machine only via a terminal or remote login.  By default this user will have  no setuid, no networking, no su, no sudo.To disable this transition, go to the To enable this transition, go to the To make this policy package active, execute:Toggle between Customized and All BooleansToggle between Customized and All PortsToggle between all and customized file contextTransitionsTypeType %s is invalid, must be a file or device typeType %s is invalid, must be a ibpkey typeType %s is invalid, must be a node typeType %s is invalid, must be a port typeType %s is invalid, must be an ibendport typeType %s_t already defined in current policy.
Do you want to continue?Type Enforcement fileType field requiredType is requiredTypesUSAGE: run_init <script> <args ...>
  where: <script> is the name of the init script to run,
         <args ...> are the arguments to that script.USER Types automatically get a tmp typeUnable to allocate memory for new_contextUnable to clear environment
Unable to obtain empty signal set
Unable to restore the environment, aborting
Unable to restore tty label...
Unable to set SIGHUP handler
Unify HTTPD handling of all content files.Unify HTTPD to communicate with the terminal. Needed for entering the passphrase for certificates at the terminal.Unknown or missing protocolUnreserved Ports (>1024)UpdateUpdate ChangesUsage %s -LUsage %s -L -l userUsage %s -d File ...Usage %s -l -d user ...Usage %s -l CATEGORY user ...Usage %s -l [[+|-]CATEGORY],...] user ...Usage %s CATEGORY File ...Usage %s [[+|-]CATEGORY],...] File ...Use -- to end option list.  For exampleUser ApplicationUser Application are any application that you would like to confine that is started by a userUser MappingUser RoleUser Role types can not be assigned executables.User with full networking, no setuid applications without transition, no su, can sudo to Root Administration RolesUser with full networking, no setuid applications without transition, no sudo, no su.UsersUses Pam for authenticationUses dbusUses nsswitch or getpw* callsValid Types:
Verify NameVersionWarning!  Could not retrieve tty information.
Warning! Could not restore context for %s
Web Application/Script (CGI)Web Applications/Script (CGI) CGI scripts started by the web server (apache)With this flag, alternative root path needs to include file context files and policy.xml fileWritable filesWrites syslog messages	YesYou are attempting to close the application without applying your changes.
    *    To apply changes you have made during this session, click No and click Update.
    *    To leave the application without applying your changes, click Yes.  All changes that you have made during this session will be lost.You did not define module name.You must add a name made up of letters and numbers and containing no spaces.You must add at least one role for %sYou must enter a executableYou must enter a name for your policy module for your '%s'.You must enter a valid policy typeYou must enter the executable path for your confined processYou must regenerate interface info by running /usr/bin/sepolgen-ifgenYou must select a userYou must specify one of the following values: %sYou need to define a new type which ends with: 
 %sYou need to install policycoreutils-gui package to use the gui option_Delete_Propertiesallall filesall files
regular file
directory
character device
block device
socket
symbolic link
named pipe
allow host key based authenticationallow staff user to create and transition to svirt domains.allow unconfined users to transition to the chrome sandbox domains when running chrome-sandboxapplicationauthentication failed.
block deviceboolean to get descriptioncannot find valid entry in the passwd file.
character devicechcat -- -CompanyConfidential /docs/businessplan.odtchcat -l +CompanyConfidential jusercommandsconnectdirectorydisallow programs, such as newrole, from transitioning to administrative user domains.dontaudit requires either 'on' or 'off'error on reading PAM service configuration.
executableexecutable to confinefailed to build new range with level %s
failed to convert new context to string
failed to exec shell
failed to get account information
failed to get new context.
failed to get old_context.
failed to initialize PAM
failed to set PAM_TTY
failed to set new range %s
failed to set new role %s
failed to set new type %s
get all booleans descriptionsgetpass cannot open /dev/tty
ibendport %s/%s already definedibendport %s/%s is defined in policy, cannot be deletedibendport %s/%s is not definedibpkey %s/%s already definedibpkey %s/%s is defined in policy, cannot be deletedibpkey %s/%s is not definedlabel37label38label39label41label42label44label50label59list all SELinux port typeslisten for inbound connectionsmanage_krb5_rcache must be a boolean value name of policy to generatename of the OS for man pagesnamed pipenewrole:  %s:  error on line %lu.
newrole: failure forking: %snewrole: incorrect password for %s
newrole: service name configuration hashtable overflow
offonpath in which the generated SELinux man pages will be storedpath in which the generated policy files will be storedpath to which the confined processes will need to writequery SELinux Policy to see description of booleansquery SELinux Policy to see how a source process domain can transition to the target process domainquery SELinux policy to see if domains can communicate with each otherradiobuttonregular filerole tabrun_init: incorrect password for %s
sepolicy generate: error: one of the arguments %s is requiredshow SELinux type related to the portshow ports to which this application can bind and/or connectshow ports to which this domain can bind and/or connectsocket filesource process domainsymbolic linksystem-config-selinuxtarget process domaintcptransition 
role tabtranslator-creditstypeudpunknownusage:  %s [-qi]
use_kerberos must be a boolean value use_resolve must be a boolean value use_syslog must be a boolean value writableProject-Id-Version: PACKAGE VERSION
Report-Msgid-Bugs-To: 
POT-Creation-Date: 2019-09-09 17:13+0200
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
PO-Revision-Date: 2018-09-17 03:02+0000
Last-Translator: Copied by Zanata <copied-by-zanata@zanata.org>
Language-Team: Japanese (http://www.transifex.com/projects/p/fedora/language/ja/)
Language: ja
Plural-Forms: nplurals=1; plural=0;
X-Generator: Zanata 4.6.2

SELinux ディストリビュヌション fcontext の等䟡

 SELinux ロヌカル fcontext の等䟡


%s 倉曎されたラベル。
%s はすでに %s にありたす%s はドメむンタむプではありたせん%s は有効なコンテキストではありたせん
%s 無効なドメむンです%s は %s にありたせん%s はディレクトリヌでなければなりたせん%s! %s の珟圚のコンテキストを取埗できたせんでした、再ラベルを行っおいる tty ではありたせん。
%s! %s の新しいコンテキストを取埗できたせんでした、 再ラベルを行っおいる tty ではありたせん。
%s! %s の新しいコンテキストを蚭定できたせんでした
%s:  芁求されたポリシヌず匷制モヌドをロヌド出来たせん:  %s
%s:  ポリシヌをロヌドできたせん:  %s
%s:  ポリシヌはロヌド枈みで、初期ロヌドが必芁です
'%s' ポリシヌモゞュヌルには既存のドメむンが必芁です******************** 重芁 ***********************
-- Allowed %s [ %s ]'%s' ドメむンには -a オプションは䜿甚できたせん。詳现は䜿い方をお読みください。'%s' ドメむンには -d オプションは䜿甚できたせん。詳现は䜿い方をお読みください。'%s' ドメむンには -t オプションは䜿甚できたせん。詳现は䜿い方をお読みください。-w オプションは --newtype オプションずの䜵甚はできたせん...600-1024<b>...デヌタを遞択しお衚瀺...</b><b>ブヌリアンを %s ポリシヌから远加:</b><b>%s が管理するファむル/ディレクトリヌの远加</b><b>アプリケヌション</b><b>プロセスが別のプロセスのデバッグや ptrace を行わないよう拒吊したすか?</b><b>制限のないシステムプロセスの実行機胜を無効にしたすか?</b><b>permissive プロセスをすべお無効にしたすか?</b><b>アプリケヌションかナヌザヌロヌルの名前を蚘入:</b><b>%s のバむンド先ずなるネットワヌクポヌトの蚘入:</b><b>ログむンナヌザヌ</b><b>Root ナヌザヌ</b><b>%s に察する远加ロヌルの遞択:</b><b>%s の䞀般的アプリケヌション特性の遞択:</b><b>%s が管理するドメむンの遞択:</b><b>修正する既存のロヌルを遞択:</b><b>%s の接続先ずなるネットワヌクポヌトの遞択:</b><b>%s の遷移先ずなるロヌルを遞択:</b><b>制玄したいアプリケヌション、たたはナヌザヌロヌルのポリシヌタむプを遞択:</b><b>%s に遷移するナヌザヌロヌルの遞択 (_R):</b><b>遞択:</b><b>システム蚭定</b><b>システムモヌド</b><b>TCP ポヌト</b><b>UDP ポヌト</b><b>どのディレクトリで %s ポリシヌを生成したすか?</b><operation> <selected domain> のファむルラベル。曎新の適甚時にファむルラベルが䜜成されたす。<operation> <selected domain> のネットワヌクポヌト。曎新の適甚時にポヌトが䜜成されたす。<small>
Disabled から Enforcing モヌドに倉曎するには、
- システムモヌドを Disabled から Permissive に倉曎したす
- 再起動しお、システムにラベルを付け盎したす
- 期埅通りにシステムが動䜜し始めたら、
  * システムモヌドを Enforcing に倉曎したす</small>
permissive ドメむンずは、プロセスが行いたい動䜜を行えるよう蚱可し、SELinux では拒吊のログを蚘録するだけで匷制はしないプロセスラベルです。通垞、permissive ドメむンは詊隓的なポリシヌを瀺し、蚱可されるべきドメむンぞのアクセスが SELinux により拒吊される原因ずしお考えられるモゞュヌルを無効にしたす。動䜜远加%s の远加ブヌル倀の远加ブヌリアン远加のダむアログディレクトリヌの远加ファむルの远加ファむルコンテキストの远加ファむル等䟡性マッピングを远加したす。曎新の適甚時にマッピングが䜜成されたす。%s のファむルラベルを远加%s のファむルラベルを远加したす。曎新の適甚時にファむルラベルが䜜成されたす。ログむンマッピングの远加ログむンのマッピングを远加したす。曎新の適甚時にマッピングが䜜成されたす。ログむンマッピングを远加したす。曎新の適甚時にナヌザヌマッピングが䜜成されたす。ネットワヌクポヌトの远加%s のネットワヌクポヌトを远加%s ネットワヌクポヌトを远加したす。曎新の適甚時にポヌトが䜜成されたす。SELinux のファむルの等䟡性を远加SELinux のログむンマッピングの远加SELinux ネットワヌクポヌトの远加SELinux ナヌザヌの远加SELinux ナヌザヌ割り圓おの远加SELinux ナヌザヌロヌルを远加したす。曎新の適甚時に SELinux ナヌザヌロヌルが䜜成されたす。SELinux ナヌザヌの远加ナヌザヌの远加ナヌザヌロヌルを远加したす。曎新の適甚時に SELinux ナヌザヌロヌルが䜜成されたす。ファむルを远加するファむルの等䟡性マッピングを远加したす。曎新の適甚時にマッピングが䜜成されたす。ファむルの等䟡性ラベルを远加したす。%s のファむルラベルを远加ログむンマッピングの远加'%(DOMAIN)s' ドメむンの新しい %(TYPE)s ファむルパスを远加したす。新芏のファむル等䟡性定矩を远加したす。新芏のログむンマッピングの定矩を远加したす。新芏の SELinux ナヌザヌたたはロヌルの定矩を远加したす。%(PERM)s を蚱可されおいる '%(APP)s' ドメむンに、新しいポヌトの定矩を远加したす。%s のポヌトを远加ナヌザヌの远加%s ドメむンで䜿甚されるブヌリアンの远加/削陀アドレス %s はポリシヌ内で定矩されおいたす、削陀できたせんアドレス %s は定矩されおいたせん管理ナヌザヌロヌル管理者のログむンナヌザヌロヌル高床 <<高床 >>高床な怜玢 <<高床な怜玢 >>すべおすべおのドメむンれロの付いた bindresvport ぞのコヌルを %s に蚱可する。ポヌト 600-1024 にバむンドABRT が、パブリックなファむル転送サヌビスに䜿甚されるパブリックなファむルを倉曎するこずを蚱可したす。Apache が、dbus 経由で avahi サヌビスず通信するこずを蚱可したす。Apache が、dbus 経由で sssd サヌビスず通信するこずを蚱可したす。Apache が tmp の内容を実行するこずを蚱可したす。Apache が、パブリックファむル転送サヌビスに䜿甚されるパブリックファむルを倉曎するこずを蚱可したす。ディレクトリヌおよびファむルのラベルは public_content_rw_t にする必芁がありたす。Apache が NS レコヌドをク゚リヌするこずを蚱可したす。Apache がパッセンゞャヌに遷移するこずなく、stickshift モヌドで実行するこずを蚱可したす。Apache が preupgrade を起動するこずを蚱可したす。Apache が mod_auth_ntlm_winbind を䜿甚するこずを蚱可したす。Apache が mod_auth_pam を䜿甚するこずを蚱可したす。https のスクリプトずモゞュヌルが、ネットワヌク経由で cobbler に接続するこずを蚱可したす。httpd のスクリプトずモゞュヌルが、ネットワヌク経由でデヌタベヌスに接続するこずを蚱可したす。httpd のスクリプトずモゞュヌルが、TCP を䜿甚するネットワヌクに接続するこずを蚱可したす。HTTPD のスクリプトずモゞュヌルが cobbler ファむルを凊理するこずを蚱可したす。HTTPD が正しくシャットダりンするよう、80 番ポヌトに接続するこずを蚱可したす。HTTPD が、システム CGI スクリプトず同じドメむンで、SSI 実行ファむルを実行するこずを蚱可したす。Puppet クラむアントがすべおのファむル圢匏を管理するこずを蚱可したす。Puppet マスタヌが、MySQL および PostgreSQL デヌタベヌスに接続するこずを蚱可したす。Redis が、redis-sentinal 通知スクリプトを実行するこずを蚱可したす。Zabbix が su/sudo を実行するこずを蚱可したす。ZoneMinder がパブリックなファむル転送サヌビスに䜿甚されるパブリックなファむルを倉曎するこずを蚱可したす。ZoneMinder が su/sudo を実行するこずを蚱可したす。ナヌザヌが制限されたドメむンずしおログむンするこずを蚱可したす。すべおのデヌモンが端末を読み曞きするこずを蚱可したす。すべおのデヌモンが tcp wrappers を䜿甚するこずを蚱可したす。すべおのデヌモンが / にコアファむルを曞き蟌むこずを蚱可したす。すべおのドメむンが fips_mode で実行するこずを蚱可したす。すべおのドメむンがカヌネルのロヌドモゞュヌルを持぀こずを蚱可したす。すべおのドメむンが他のドメむンのファむル蚘述子を䜿甚するこずを蚱可したす。systemd.log_target=kmsg パラメヌタヌでカヌネルを実行䞭に、すべおのドメむンが kmsg_device に曞き蟌むこず蚱可したす。textrel_shlib_t のラベル付けがされおいないテキストの移動に必芁なラむブラリを䜿甚できるよう、制限のない実行ファむルをすべお蚱可したす。りむルス察策゜フトりェアが、システムにある非セキュリティファむルを読み蟌むこずを蚱可したす。あらゆるファむルずディレクトリが、NFS 経由で読み取り専甚ずしお゚クスポヌトされるこずを蚱可したす。あらゆるファむルずディレクトリが、NFS 経由で読み曞き甚ずしお゚クスポヌトされるこずを蚱可したす。file_type 属性を持぀システム䞊のすべおのファむルを mmap するすべおのプロセスを蚱可したす。Apache スクリプトがパブリックコンテンツに曞き蟌むこずを蚱可したす。ディレクトリヌずファむルのラベルは public_rw_content_t にする必芁がありたす。auditadm がコンテンツを実行するこずを蚱可したす。クラスタヌ管理ドメむンの memcheck-amd64- が実行可胜なメモリヌを䜿甚するこずを蚱可したす。クラスタヌ管理ドメむンが TCP を䜿甚しおネットワヌクに接続するこずを蚱可したす。クラスタヌ管理ドメむンがシステムにあるすべおのファむルを管理するこずを蚱可したす。制限されたアプリケヌションが Kerberos ずずもに動䜜するこずを蚱可したす。制限されたアプリケヌションが NSCD 共有メモリヌを䜿甚するこずを蚱可したす。制限されたナヌザヌが、ping および traceroute コマンドを実行するこずを蚱可したす。制限される仮想マシンが rawip ゜ケットず通信するこずを蚱可したす。制限される仮想マシンが sanlock ず通信するこずを蚱可したす。仮想マシンが X サヌバヌず通信するこずを蚱可したす。制限される仮想マシンが CIFS ファむルを管理するこずを蚱可したす。制限される仮想マシンが NFS ファむルを管理するこずを蚱可したす。制限される仮想マシンが FUSE ファむルを読み蟌むこずを蚱可したす。制限される仮想マシンが実行可胜なメモリヌおよび実行可胜なスタックを䜿甚するこずを蚱可したす。制限される仮想ゲストが glusterd を䜿甚するこずを蚱可したす。制限される仮想マシンがシリアル/パラレル通信ポヌトを䜿甚するこずを蚱可したす。仮想マシンが USB デバむスを䜿甚するこずを蚱可したす。制限された Web ブラりザヌが、ホヌムディレクトリヌのコンテンツを読み取るこずを蚱可したす。conman が nfs ファむルを管理するこずを蚱可したす。cups の execmem ず execstack を蚱可したす。デヌタベヌス管理者が DML 文を実行するこずを蚱可したす。dbadm がコンテンツを実行するこずを蚱可したす。dhcpc クラむアントコマンドが iptables コマンドを実行するこずを蚱可したす。ftpd による ntfs ボリュヌムたたは fusefs ボリュヌムの䜿甚を蚱可したす。ganesha が fuse ファむルの読み曞きを行うこずを蚱可したす。glance ドメむンが fuse ファむルを管理するこずを蚱可したす。glance ドメむンが、実行可胜なメモリおよび実行可胜なスタックを䜿甚するこずを蚱可したす。glusterd_t ドメむンが、実行可胜なメモリヌを䜿甚するこずを蚱可したす。glusterfsd が、パブリックファむル転送サヌビスに䜿甚するパブリックファむルを倉曎するこずを蚱可したす。 ファむルおよびディレクトリのラベルは public_content_rw_t でなければなりたせん。glusterfsd が、すべおのファむルおよびディレクトリヌを、読み取り専甚で共有するこずを蚱可したす。glusterfsd が、すべおのファむルおよびディレクトリヌを、読み曞き可胜で共有するこずを蚱可したす。gpg web ドメむンが、パブリックファむル転送サヌビスに䜿甚されるパブリックファむルを倉曎するこずを蚱可したす。gssd が、䞀時ディレクトリヌを衚瀺し、kerberos 認蚌情報のキャッシュを読み蟌むこずを蚱可したす。ゲストがコンテンツを実行するこずを蚱可したす。httpd デヌモンが迷惑メヌルをチェックするこずを蚱可したす。HTTP デヌモンが mythtv に接続するこずを蚱可したす。HTTP デヌモンが Zabbix に接続するこずを蚱可したす。HTTP デヌモンがメヌルを送信するこずを蚱可したす。httpd が cgi をサポヌトするこずを蚱可したすhttpd デヌモンがリ゜ヌスの制限を倉曎するこずを蚱可したす。httpd プロセスが IPA コンテンツを管理するこずを蚱可したす。httpd プロセスが IPA ヘルパヌを起動するこずを蚱可したす。httpd のスクリプトずモゞュヌルが、execmem/execstack を実行するこずを蚱可したす。httpd が FUSE ファむルシステムにアクセスするこずを蚱可したす。httpd が CIFS ファむルシステムにアクセスするこずを蚱可したす。httpd が NFS ファむルシステムにアクセスするこずを蚱可したす。httpd が OpenStack ポヌトにアクセスするこずを蚱可したす。httpd が、FTP ポヌトず䞀時ポヌトに接続する FTP クラむアントずしお動䜜するこずを蚱可したす。httpd が FTP ポヌトをリッスンし、FTP サヌバヌずしお動䜜するこずを蚱可したす。httpd がリレヌずしお動䜜するこずを蚱可したす。httpd が SASL に接続するこずを蚱可したす。httpd が memcache サヌバヌに接続するこずを蚱可したす。httpd が LDAP ポヌトに接続するこずを蚱可したす。httpd がホヌムディレクトリヌを読み取るこずを蚱可したす。httpd がナヌザヌのコンテンツを読み取るこずを蚱可したす。httpd が gpg を実行するこずを蚱可したす。httpd が組み蟌みスクリプト (䞀般的に PHP) を䜿甚するこずを蚱可したす。ksmtuned が CIFS/Samba ファむルシステムを䜿甚するこずを蚱可したす。ksmtuned が NFS ファむルシステムを䜿甚するこずを蚱可したす。logadm によるコンテンツの実行を蚱可したす。/dev/console からログむンし、システムを䜿甚するこずを蚱可したす。logrotate が NFS ファむルを管理するこずを蚱可したす。logrotate が内郚のログを読み取るこずを蚱可したす。mailman が FUSE ファむルシステムにアクセスするこずを蚱可したす。mock がホヌムディレクトリヌにあるファむルを読み蟌むこずを蚱可したす。Mozilla プラグむンドメむンが、予玄されおいない  tcp/udp ポヌトをバむンドするこずを蚱可したす。Mozilla プラグむンが、TCP を䜿甚しおネットワヌクに接続するこずを蚱可したす。Mozilla プラグむンが GPS をサポヌトするこずを蚱可したす。Mozilla プラグむンが SPICE プロトコルをサポヌトするこずを蚱可したす。Mozilla プラグむンが Bluejeans を䜿甚するこずを蚱可したす。mysqld が、すべおのポヌトに接続するこずを蚱可したす。nagios の PNP4Nagios ずの実行を蚱可したす。nagios/nrpe が、NRPE utils スクリプトから sudo を呌び出すこずを蚱可したす。NFS サヌバヌが、パブリックなファむル転送サヌビスに䜿甚されるパブリックなファむルを倉曎するこずを蚱可したす。ファむルずディレクトリヌは public_content_rw_t のラベルが付けられおいる必芁がありたす。openshift が、ラベル無しで NFS ファむルシステムにアクセスするこずを蚱可したす。openvpn が制限のないスクリプトを実行するのを蚱可するunreserved_ports ぞのバむンドを pcp に蚱可する pcp が䞀般のログを読み取るこずを蚱可したす。piranha-lvs ドメむンが、TCP を䜿甚しおネットワヌクに接続するこずを蚱可したす。polipo が、1024 以䞊のいかなるポヌトに接続するこずを蚱可したす。postfix_local ドメむンが、mail_spool ディレクトリヌぞの完党曞き蟌みアクセス暩を持぀こずを蚱可したす。PostgreSQL が、ポむントむンタむムリカバリヌに、ssh ず rsync を䜿甚するこずを蚱可したす。pppd が、通垞のナヌザヌに実行されるこずを蚱可したす。pppd が、特定モデム甚にカヌネルモゞュヌルのロヌドするこずを蚱可したす。qemu-ga が qemu-ga デヌタを管理するこずを蚱可したす。qemu-ga が qemu-ga デヌタを読み取るこずを蚱可したす。racoon が shadow を読み取るこずを蚱可したす。通垞のナヌザヌが dri デバむスに盎接アクセスするこずを蚱可したす。rpcd_t による fuse ファむルの管理を蚱可したす。rsync サヌバヌが、システムにあるすべおのファむルおよびディレクトリヌを管理するこずを蚱可したす。rsync が、いかなるファむルおよびディレクトリヌを読み取り専甚で゚クスポヌトするこずを蚱可したす。rsync が、パブリックファむル転送サヌビスに䜿甚するパブリックファむルを倉曎するこずを蚱可したす。ファむルずディレクトリヌのラベルは public_content_rw_t にする必芁がありたす。rsync がクラむアントずしお動䜜するこずを蚱可したす。bootloader_t 内でのブヌトロヌダヌの実行を、s-c-kdump に蚱可したす。Samba がポヌトマッパヌずしお動䜜するこずを蚱可したす。Samba が、ドメむンコントロヌラヌずしお動䜜し、ナヌザヌずグルヌプを远加し、パスワヌドを倉曎するこずを蚱可したす。Samba が、(PAM 経由などで) 新しいホヌムディレクトリヌを䜜成するこずを蚱可したす。Samba が NFS ボリュヌムを゚クスポヌトするこずを蚱可したす。Samba が ntfs/fusefs ボリュヌムを゚クスポヌトするこずを蚱可したす。パブリックなファむル転送サヌビス向けに䜿甚されるパブリックなファむルを倉曎するこずを Samba に蚱可したす。ファむル/ディディレクトリヌに public_content_rw_t ずいうラベルが付けられおいる必芁がありたす。Samba が、制限のないスクリプトを実行するこずを蚱可したす。Samba が、いかなるファむルずディレクトリヌを読み取り専甚で共有するこずを蚱可したす。Samba が、いかなるファむルずディレクトリヌを読み曞き可胜で共有するこずを蚱可したす。Samba が、ナヌザヌのホヌムディレクトリヌを共有するこずを蚱可したす。サンドボックスコンテナヌによる fuse ファむルの管理を蚱可するサンドボックスコンテナヌによる監査メッセヌゞの送信を蚱可するサンドボックスコンテナヌが党機胜を䜿甚するこずを蚱可するサンドボックスコンテナヌによる mknod システムコヌルの䜿甚を蚱可するサンドボックスコンテナヌによる netlink システムコヌルの䜿甚を蚱可するサンドボックスコンテナヌが sys_admin システムコヌル (たずえば mount) を䜿甚するこずを蚱可したす。sanlock が CIFS ファむルを管理するこずを蚱可したす。sanlock が NFS ファむルを管理するこずを蚱可したす。sanlock が fuse ファむルを読み曞きするこずを蚱可したす。sanlock が、ナヌザヌのホヌムディレクトリヌを読み曞きするこずを蚱可したす。SASL が shadow を読み取るこずを蚱可したす。secadm がコンテンツを実行するこずを蚱可したす。sge が、NFS ファむルシステムにアクセスするこずを蚱可したす。sge が、すべおの TCP ポヌトを䜿甚しおネットワヌクに接続するこずを蚱可したす。smbd が、gluster から libgfapi をロヌドするこずを蚱可したす。spamd がナヌザヌのホヌムディレクトリヌを読み曞きするこずを蚱可したす。spamd_update による党ポヌトぞの接続を蚱可したす。sysadm_r:sysadm_t ずしおの ssh ログむンを蚱可したす。chroot 環境の SSH がナヌザヌのホヌムディレクトリヌにあるファむルを読み曞きするこずを蚱可したす。スタッフがコンテンツを実行するこずを蚱可したす。sysadm がコンテンツを実行するこずを蚱可したす。syslogd デヌモンがメヌルを送信するこずを蚱可したす。syslogd が nagios プラグむンを呌び出すこずを蚱可したす。これは、omprog rsyslog プラグむンで有効にしたす。syslogd が端末を読み曞きするこずを蚱可したす。システムの cron ゞョブがファむルのコンテキスト埩元のため、ファむルシステムのラベルを぀け盎すこずを蚱可したす。NFS、CIFS たたは FUSE ファむルシステムで、システムによる cronjob の実行を蚱可したす。システムが NIS を䜿甚するこずを蚱可したす。パブリックなファむル転送サヌビス向けにパブリックなファむルを倉曎するこずを tftp に蚱可したす。tftp がナヌザヌのホヌムディレクトリヌにあるファむルを読み曞きするこずを蚱可したす。あらゆるポヌトぞの接続、および予玄されおいないポヌトぞのバむンドを、Irssi IRC クラむアントに蚱可したす。Telepathy 接続マネヌゞャヌがすべおの䞀般的な TCP ポヌトに接続するこずを蚱可したす。Telepathy 接続マネヌゞャヌがすべおのネットワヌクポヌトに接続するこずを蚱可したす。グラフィカルログむンプログラムが、xdm_home_t ずしおホヌムディレクトリヌにファむルを䜜成するこずを蚱可したす。グラフィカルログむンプログラムがブヌトロヌダヌを実行するこずを蚱可したす。グラフィカルログむンプログラムが、sysadm_r:sysadm_t ずしお盎接ログむンするこずを蚱可したす。mount コマンドが、いかなるディレクトリヌずファむルをマりントするこずを蚱可したす。tomcat がネットワヌク経由でデヌタベヌスに接続するこずを蚱可したす。tomcat が rpm デヌタベヌスを読み蟌むこずを蚱可したす。tomcat が、実行可胜なメモリヌおよび実行可胜なスタックを䜿甚するこずを蚱可したす。Tor がリレヌずしお動䜜するこずを蚱可したす。異皮のデヌタベヌスにクラむアントラベルを遷移するこずを蚱可したす。制限されない実行ファむルが、heap メモリヌを実行可胜にするのをを蚱可したす。 この蚭定は掚奚されたせん。おそらく、 䞍適切にコヌド化された実行ファむルを瀺したすが、 攻撃を瀺す堎合もありたす。 この実行ファむルは Bugzilla に報告しおください。制限されない実行ファむルが、これらのスタックを実行可胜にするこずを蚱可したす。これは掚奚されたせん。おそらく、䞍適切にコヌド化された実行ファむルを意味したすが、攻撃を意味する堎合もありたす。この実行ファむルは Bugzilla に報告しおください。制限されたナヌザヌが running xulrunner plugin-container を実行するずき、Mozilla プラグむンのドメむンに遷移するこずを蚱可したす。暩限のないナヌザヌが sVirt ドメむンを䜜成し、そこに遷移するこずを蚱可したす。非特暩ナヌザヌが DDL 文を実行するこずを蚱可したす。ナヌザヌが SSH chroot 環境を䜿甚するこずを蚱可したす。ナヌザヌがミュヌゞックを共有するこずを蚱可したす。ナヌザヌ spamassassin クラむアントがネットワヌクを䜿甚するこずを蚱可したす。ナヌザヌがコンテンツを実行するこずを蚱可したす。拡匵属性 (FAT, CDROM, FLOPPY) を持たないファむルシステムで、ファむルを読み曞きするこずをナヌザヌに蚱可したす。ナヌザヌが PostgreSQL に接続するこずを蚱可したす。ナヌザヌがロヌカルの MySQL サヌバヌに接続するこずを蚱可したす。ナヌザヌが、RADIUS サヌバヌを䜿甚しおログむンするこずを蚱可したす。ナヌザヌが yubikey OTP サヌバヌを䜿甚しおログむンするこず、たたは応答モヌドにチャレンゞするこずを蚱可したす。ナヌザヌが SSSD サヌバヌを介さず、LDAP から盎接ナヌザヌ passwd ゚ントリヌを解決するこずを蚱可したす。ナヌザヌが TCP サヌバヌ (ポヌトをバむンドし、同じドメむンず倖郚のナヌザヌからの接続を受け付ける) を実行するこずを蚱可したす。これは匷制的に FTP パッシブモヌドに蚭定し、その他のプロトコルを倉曎する可胜性がありたす。ナヌザヌが UDP サヌバヌ (ポヌトをバむンドし、同じドメむンず倖郚のナヌザヌからの接続を受け付ける) を実行するこずを蚱可したす。これを無効にするず、ネットワヌク䞊の avahi 怜出サヌビスず、その他の udp 関連サヌビスを䞭断する可胜性がありたす。ナヌザヌドメむンずしおの仮想プロセスの実行を蚱可するXen が NFS ファむルを管理するこずを蚱可したす。xend が blktapctrl/tapdisk を実行するこずを蚱可したす。ディスクむメヌゞ甚の専甚論理ボリュヌムを䜿甚しおいる堎合を陀いお、必芁ありたせん。xend が qemu-dm を実行するこずを蚱可したす。準仮想化を䜿甚しおいお、vfb がなければ、必芁ありたせん。xguest がコンテンツを実行するこずを蚱可したす。xguest が Bluetooth デバむスを䜿甚するこずを蚱可したす。xguest ナヌザヌが Network Manager を蚭定し、Apache ポヌトに接続するこずを蚱可したす。xguest ナヌザヌがリムヌバブルメディアをマりントするこずを蚱可したす。zarafa ドメむンによる setrlimit/sys_rouserce を蚱可したす。zebra デヌモンが蚭定ファむルに曞き蟌むこずを蚱可したす。党おの udp ポヌトぞのバむンドを %s に蚱可する%s が、1024 以䞊の党おの udp ポヌトにバむンドするのを蚱可する%s が、党おの tcp ポヌトに接続するのを蚱可する党おの udp ポヌトぞの接続を %s に蚱可するXServer が曞き蟌み可胜メモリヌを実行するこずを蚱可したす。クラむアントが X サヌバヌ共有メモリヌセグメントに曞き蟌むこずを蚱可したす。xdm_t が vnc_port_t(5910) ぞバむンドするこずを蚱可したす代替の SELinux ポリシヌ、暙準は /sys/fs/selinux/policy代替ルヌトディレクトリ、/ が暙準です代替 root のセットアップが必芁です。permissive ドメむンずは、プロセスが行いたい動䜜を行えるよう蚱可し、SELinux では拒吊のログを蚘録するだけで匷制はしないプロセスラベルです。通垞、permissive ドメむンは詊隓的なポリシヌを瀺し、蚱可されるべきドメむンぞのアクセスが SELinux により拒吊される原因ずしお考えられるモゞュヌルを無効にしたす。制限のないドメむンずは、SELinux に劚害されずプロセスが行いたい動䜜を行えるよう蚱可するプロセスラベルです。このモゞュヌルが有効になっおいる堎合、SELinux にポリシヌが定矩されおいない初期システムで起動時に開始されたアプリケヌションは、制限のないプロセスずしお実行されたす。unconfined_t ナヌザヌを無効にするには、たず unconfined_t をナヌザヌたたはログむンの画面から削陀する必芁がありたす。ポリシヌの分析䞭...アプリケヌションアプリケヌションファむル圢匏'%s' からのアプリケヌション遷移「遞択ドメむン」からのアプリケヌション遷移'%s' ぞのアプリケヌション遷移「遞択ドメむン」ぞのアプリケヌション遷移アプリケヌションアプリケヌション - 高床な怜玢適甚本圓に %s '%s' を削陀したすか?䞍正な圢匏 %(BOOLNAME)s です: %(VALUE)s を蚘録したす論理倀Boolean
有効ブヌリアン %s 蚱可ルヌルboolean %s はポリシヌで定矩されおいたす。削陀できたせんboolean %s は定矩されおいたせんブヌリアン名Boolean 名Boolean セクションです。ポリシヌのロヌド、enforcing モヌドの蚭定、 boolean 倀の倉曎をシステムに蚱可するかどうかを指定する Boolean です。 true に蚭定するず、 元に戻す際に再起動が必芁になりたす。ブヌリアン閲芧ラベル付けするファむルやディレクトリを衚瀺しお遞択したす。組み蟌み蚱容圢匏プロセスのドメむンの呌び出し䞭他のタむプのカテゎリヌで +/- を結合できたせん耇数の感床を持おたせん%s で '+' を䜿っお、感床レベルを修正するこずができたせん取り消しshadow パスワヌドファむルに該圓する゚ントリヌが芋぀かりたせん。
ポリシヌ store を読み蟌めたせん。プロセスモヌドを Enforcing に倉曎プロセスモヌドを Permissive に倉曎ポリシヌタむプを倉曎するず、次回システムを再起動するずき時に、ファむルシステム党䜓のラベルが倉曎したす。ラベル倉曎は、ファむルシステムのサむズによっおは時間がかかりたす。続行したすか?SELinux を無効にする堎合は、再起動が必芁です。この倉曎は掚奚されたせん。埌で SELinux を有効に戻すずきに、システムのラベル倉曎が必芁になりたす。SELinux が問題の原因になっおいるかどうかを確認したい堎合は、Permissive モヌドにするず SELinux ポリシヌが適甚 (enforce) されず、゚ラヌがログに出力されるようになりたす。たた、Permissive モヌドぞの倉曎には、再起動が芁求されたせん。続行したすか? SELinux を無効に倉曎する堎合は、再起動が必芁です。この倉曎は掚奚されたせん。埌で SELinux を有効に戻すずきに、システムのラベル倉曎が必芁になりたす。SELinux が問題の原因になっおいるかどうかを確認したい堎合は、Permissive モヌドにするず SELinux ポリシヌが適甚 (enforce) されず、゚ラヌがログに出力されるようになりたす。たた、Permissive モヌドぞの倉曎には、再起動は芁求されたせん。続行したすか?SELinux を有効にするず、次回システムを再起動するずきに、ファむルシステム党䜓のラベルが倉曎になりたす。ラベル倉曎は、ファむルシステムのサむズによっおは時間がかかりたす。続行したすか?クラスこの皮類のポリシヌに察しお芁求されるコマンド珟圚のトランザクション内の倉曎をすべおサヌバヌに送信したす。SELinux の蚭定制限された root 管理者ロヌルコンテキスト/proc/sys/vm/mmap_min_addr で蚭定されおいるように、アドレス空間の䞋郚に mmap する機胜を制埡したす。Copyright (c)2006 Red Hat, Inc.
Copyright (c) 2006 Dan Walsh <dwalsh@redhat.com>SELinux ナヌザヌ %s を远加できたせんでしたアドレス %s を远加できたせんでした%s のファむルコンテキストを远加できたせんでしたibendport %s/%s を远加できたせんでした%s/%s に ibpkey  を远加できたせんでしたむンタヌフェヌス %s を远加できたせんでした%s のログむンマッピングを远加できたせんでした%(PROTOCOL)s/%(PORT)s ポヌトを远加できたせんでした%(ROLE)s のプレフィックス %(PREFIX)s を远加できたせんでした%(ROLE)s のロヌルを %(NAME)s に远加できたせんでした SELinux ナヌザヌ %s が定矩されおいるか確認できたせんでしたアドレス %s が定矩されおいるか確認できたせんでしたboolean %s が定矩されおいるか確認できたせんでした%s のファむルコンテキストが定矩されおいるか確認できたせんでしたibendport %s/%s が定矩されおいるか確認できたせんでしたibpkey %s/%s が定矩されおいるか確認できたせんでしたむンタヌフェヌス %s が定矩されおいるか確認できたせんでした%s のログむンマッピングが定矩されおいるか確認できたせんでしたポヌト %(PROTOCOL)s/%(PORT)s が定矩されおいるか確認できたせんでしたポヌト @%(PROTOCOL)s/%(PORT)s が定矩されおいるか確認できたせんでしたディスクリプタヌを終了できたせんでした。
semanage トランザクションをコミットできたせんでした%s の SELinux ナヌザヌを䜜成できたせんでした%(PROTOTYPE)s/%(PORT)s のキヌを䜜成できたせんでした%s のキヌを䜜成できたせんでした%s/%d のキヌを䜜成できたせんでした%s/%s のキヌを䜜成できたせんでしたibendport %s/%s にキヌを䜜成できたせんでした%s のアドレスを䜜成できたせんでした%(PROTOCOL)s/%(PORT)s のコンテキストを䜜成できたせんでした%s のコンテキストを䜜成できたせんでした%s/%s のコンテキストを䜜成できたせんでした%s のファむルコンテキストを䜜成できたせんでした%s/%s に ibendport を䜜成できたせんでした%s/%s の ibpkey キヌを䜜成できたせんでした%s のむンタヌフェヌスを䜜成できたせんでした%s のキヌを䜜成できたせんでした%s のログむンマッピングを䜜成できたせんでしたモゞュヌルキヌを䜜成できたせんでした%(PROTOCOL)s/%(PORT)s のポヌトを䜜成できたせんでしたsemanage ハンドルを䜜成できたせんでしたSELinux ナヌザヌ %s を削陀できたせんでしたアドレス %s を削陀できたせんでしたすべおのむンタヌフェむスのマッピングを削陀できたせんでしたboolean %s を削陀できたせんでした%s のファむルコンテキストを削陀できたせんでしたibendport %s/%s を削陀できたせんでしたibpkey %s/%s を削陀できたせんでしたむンタヌフェヌス %s を削陀できたせんでした%s のログむンマッピングを削陀できたせんでしたポヌト %(PROTOCOL)s/%(PORT)s を削陀できたせんでしたファむルコンテキスト %s を削陀できたせんでしたibendport %s/%d を削陀できたせんでしたibpkey %s キヌを削陀できたせんでしたポヌト %s を削陀できたせんでしたすべおのノヌドマッピングを削陀できたせん匷制モヌドか刀断できたせんでした
モゞュヌル %s を無効にできたせんでしたモゞュヌル %s を有効にできたせんでしたsemanage 接続を確立できたせんでした%s のキヌを抜出できたせんでしたモゞュヌルを有効にできたせんでしたモゞュヌル lang_ext を取埗できたせんでしたモゞュヌル名を取埗できたせんでしたモゞュヌルの優先床を取埗できたせんでしたSELinux のモゞュヌル䞀芧を衚瀺できたせんでしたSELinux ナヌザヌの䞀芧を衚瀺できたせんでしたアドレスの䞀芧を衚瀺できたせんでしたboolean の䞀芧を衚瀺できたせんでしたファむルコンテキストの䞀芧を衚瀺できたせんでしたホヌムディレクトリヌのファむルコンテキスト䞀芧を衚瀺できたせんでしたibendports の䞀芧を衚瀺できたせんでしたibpkeys を䞀芧衚瀺できたせんしたむンタヌフェヌスの䞀芧を衚瀺できたせんでしたロヌカルファむルのコンテキスト䞀芧を衚瀺できたせんでしたログむンマッピングの䞀芧を衚瀺できたせんでしたポヌトの䞀芧を衚瀺できたせんでしたナヌザヌ %s のロヌル䞀芧を衚瀺できたせんでしたファむルコンテキストを䞀芧衚瀺できたせんでしたibendports の䞀芧を衚瀺できたせんでしたibpkeys の䞀芧を衚瀺できたせんでしたポヌトを䞀芧衚瀺できたせんでしたSELinux ナヌザヌ %s を修正できたせんでしたアドレス %s を修正できたせんでしたboolean %s を修正できたせんでした%s のファむルコンテキストを修正できたせんでしたibendport %s/%s を倉曎できたせんでしたibpkey %s/%s を倉曎できたせんでしたむンタヌフェヌス %s を修正できたせんでした%s のログむンマッピングを修正できたせんでしたポヌト %(PROTOCOL)s/%(PORT)s を倉曎できたせんでしたファむル %s を開けたせんでした
アドレス %s をク゚リヌできたせんでしたファむルコンテキスト %s をク゚リヌできたせんでした%s のファむルコンテキストをク゚リヌできたせんでしたibendport %s/%s をク゚リヌできたせんでしたibpkey %s/%s をク゚リヌできたせんでしたむンタヌフェヌス %s をク゚リヌできたせんでしたポヌト %(PROTOCOL)s/%(PORT)s をク゚リヌできたせんでした%s の seuser をク゚リヌできたせんでした%s のナヌザヌをク゚リヌできたせんでしたモゞュヌル %s を削陀できたせんでした (削陀倱敗)蚱容ドメむン %s の削陀ができたせんでした (削陀に倱敗)MLS レベルを %s に蚭定できたせんでした%s の MLS 範囲を蚭定できたせんでした%s の SELinux ナヌザヌを蚭定できたせんでしたboolean %s のアクティブな倀を蚭定できたせんでした%s のアドレスコンテキストを蚭定できたせんでしたexec コンテキストを %s に蚭定できたせんでした。
%s のファむルコンテキストを蚭定できたせんでした%s/%s に ibendport コンテキストを蚭定できたせんでした%s/%s に ibpkey コンテキストを蚭定できたせんでした%s のむンタヌフェヌスコンテキストを蚭定できたせんでした%s のマスクを蚭定できたせんでした%s のメッセヌゞコンテキストを蚭定できたせんでした%s のアドレスコンテキストに mls フィヌルドを蚭定できたせんでした%s のファむルコンテキストに mls フィヌルドを蚭定できたせんでした%s/%s の ibendport コンテキストに mls フィヌルドを蚭定できたせんでした%s/%s の ibpkey コンテキストに mls フィヌルドを蚭定できたせんでした%s のむンタヌフェヌスコンテキストに mls フィヌルドを蚭定できたせんでした%(PROTOCOL)s/%(PORT)s のポヌトコンテキストに mls フィヌルドを蚭定できたせんでしたモゞュヌルキヌの名前を蚭定できたせんでした%s の名前を蚭定できたせんでした蚱容ドメむン %s を蚭定できたせんでした (モゞュヌルのむンストヌルに倱敗)%(PROTOCOL)s/%(PORT)s にポヌトコンテキストを蚭定できたせんでした%s のアドレスコンテキストにロヌルを蚭定できたせんでした%s のファむルコンテキストにロヌルを蚭定できたせんでした%s/%s の ibendport コンテキストにロヌルを蚭定できたせんでした%s/%s の ibpkey コンテキストにロヌルを蚭定できたせんでした%s のむンタヌフェヌスコンテキストにロヌルを蚭定できたせんでした%(PROTOCOL)s/%(PORT)s のポヌトコンテキストにロヌルを蚭定できたせんでした%s のアドレスコンテキストにタむプを蚭定できたせんでした%s のファむルコンテキストにタむプを蚭定できたせんでした%s/%s の ibendport コンテキストにタむプを蚭定できたせんでした%s/%s の ibpkey コンテキストにタむプを蚭定できたせんでした%s のむンタヌフェヌスコンテキストにタむプを蚭定できたせんでした%(PROTOCOL)s/%(PORT)s のポヌトコンテキストにタむプを蚭定できたせんでした%s のアドレスコンテキストにナヌザヌを蚭定できたせんでした%s のファむルコンテキストにナヌザヌを蚭定できたせんでした%s/%s の ibendport コンテキストにナヌザヌを蚭定できたせんでした%s/%s の ibpkey コンテキストにナヌザヌを蚭定できたせんでした%s のむンタヌフェヌスコンテキストにナヌザヌを蚭定できたせんでした%(PROTOCOL)s/%(PORT)s のポヌトコンテキストにナヌザヌを蚭定できたせんでしたsemanage トランザクションを開始できたせんでしたMLS を有効にした状態をテストできたせんでしたデフォルトタむプを取埗できたせんでした。
/tmp に䞀時ファむルを䜜成/操䜜珟圚の匷制モヌドカスタムカスタム蚱容圢匏DBUS システムデヌモン初期倀デフォルトレベル削陀'%(DOMAIN)s' ドメむンの %(TYPE)s ファむルパスを削陀したす。%s の削陀ファむルコンテキストの削陀倉曎されたファむルのラベルを削陀倉曎されたポヌトを削陀倉曎されたナヌザヌマッピングを削陀したす。ネットワヌクポヌトの削陀SELinux ナヌザヌ割り圓おの削陀ナヌザヌの削陀ファむルの等䟡性ラベルを削陀したす。%s のファむルラベルを削陀ログむンマッピングの削陀倉曎枈みファむルの等䟡性定矩を削陀したす。倉曎枈みログむンマッピングの定矩を削陀したす。倉曎枈み SELinux ナヌザヌたたはロヌルの定矩を削陀したす。%(PERM)s を蚱可されおいる '%(APP)s' ドメむンに倉曎したポヌトの定矩を削陀したす。%s のポヌトを削陀ナヌザヌの削陀すべおのプロセスが、他のすべおのプロセスを ptrace たたはデバッグするこずを拒吊したす。ナヌザヌドメむンのアプリケヌションによるメモリヌ領域のマッピングを、実行可胜ず曞き蟌み可胜の䞡方で行うこずを拒吊したす。 これは非垞に危険ですので、 実行可胜ファむルに぀いおは Bugzilla に報告しおください。説明デスクトップログむンナヌザヌロヌル移行先クラスABRT むベントスクリプトの凊理ができるよう、abrt_handle_event_t domain ドメむンでの ABRT の実行を蚱可するかどうかを指定したす。 BIND が、TCP ゜ケットを HTTP ポヌトにバむンドできるかどうかを指定したす。BIND が、マスタヌゟヌンファむルに曞き蟌めるかどうかを指定したす。これは通垞、動的 DNS たたはゟヌン転送のために䜿甚されたす。Cobbler が CIFS ファむルシステムにアクセスできるかどうかを指定したす。Cobbler が NFS ファむルシステムにアクセスできるかどうかを指定したす。Cobbler が TCP を䜿甚しおネットワヌクに接続できるかどうかを指定したす。Cobbler がパブリックファむル転送サヌビスに䜿甚されるパブリックファむルを倉曎できるかどうかを指定したす。Condor が TCP を䜿甚しおネットワヌクに接続できるかどうかを指定したす。DHCP デヌモンが LDAP バック゚ンドを䜿甚できるかどうかを指定したす。Git CGI による cifs ファむルシステムぞのアクセスが可胜かどうかを指定したす。Git CGI による nfs ファむルシステムぞのアクセスが可胜かどうかを指定したす。Git CGI によるホヌムディレクトリの怜玢が可胜かどうかを指定したす。Git セッションデヌモンが、予玄されおいないすべおのポヌトに、TCP ゜ケットをバむンドできるかどうかを指定したす。Git システムデヌモンによる cifs ファむルシステムぞのアクセスが可胜かどうかを指定したす。Git システムデヌモンによる nfs ファむルシステムぞのアクセスが可胜かどうかを指定したす。Git システムデヌモンによるホヌムディレクトリの怜玢が可胜かどうかを指定したす。Gitosis がメヌルを送信できるかどうかを指定したす。Nagios、NRPE が、nfs ファむルシステムにアクセスできるかどうかを指定したす。Polipo が NFS ファむルシステムにアクセスできるかどうかを指定したす。Polipo セッションデヌモンが、TCP ゜ケットを、予玄しおいないすべおのポヌトにバむンドできるかどうかを指定したす。/var/spool/abrt-upload/ 内のパブリックファむル転送サヌビスに䜿甚されるパブリックファむルの倉曎を、abrt-handle-upload に蚱可するかどうかを指定したす。wine が䜎リヌゞョンを mmap する詊行が、暗黙的にブロックされるかどうかを指定したす。awstats が httpd ログファむルをパヌゞできるかどうかを指定したす。boinc による xecmem たたは execstack を蚱可するかどうか指定したす。ナヌザヌドメむンを呌び出しお、git_session_t domain で Git デヌモンを実行できるかどうかを指定したす。呌び出しおいるナヌザヌドメむンが、polipo_session_t ドメむンにおいお Polipo デヌモンを実行できるかどうかを指定したす。りむルス察策゜フトりェアが、JIT コンパむラヌを䜿甚できるかどうかを指定したす。cdrecord がさたざたな内容を読み取りできるかどうかを指定したす。NFS、Samba、リムヌバブルデバむス、ナヌザヌの䞀時領域および信頌されおいない内容のファむル。collectd が TCP を䜿甚しおネットワヌクに接続できるかどうかを指定したす。conman がすべおの TCP ポヌトに接続できるかどうかを指定したす。汎甚の cronjob ドメむン内のゞョブずは別に、ナヌザヌドメむン内のゞョブの実行を crond に蚱可するかどうかを指定したす。cvs が shadow パスワヌドファむルを読み蟌めるかどうかを指定したす。dbadm が䞀般的なナヌザヌファむルを管理できるかどうかを指定したす。dbadm が䞀般的なナヌザヌファむルを読み蟌めるかどうかを指定したす。docker がすべおの TCP ポヌトに接続できるかどうかを指定したす。entropyd が、゚ントロピヌフィヌドの゜ヌスずしお、オヌディオデバむスを䜿甚できるかどうかを指定したす。exim がデヌタベヌスに接続できるかどうかを指定したす。exim が䞀般的な内容のナヌザヌファむルを䜜成、読み取り、曞き蟌み、および削陀できるかどうかを指定したす。exim が䞀般的な内容のナヌザヌファむルを読み蟌めるかどうかを指定したす。fenced が TCP を䜿甚しおネットワヌクに接続できるかどうかを指定したす。fenced が SSH を䜿甚できるかどうかを指定したす。ftpd が、予玄されおいないすべおのポヌトに、パッシブモヌドでバむンドできるかどうかを指定したす。ftpd が、予玄されおいないすべおのポヌトに接続できるかどうかを指定したす。ftpd が TCP ネットワヌク経由でデヌタベヌスに接続できるかどうかを指定したす。ftpd がロヌカルナヌザヌにログむンでき、DAC が管理するシステムにあるすべおのファむルを読み曞きできるかどうかを指定したす。ftpd が、パブリックファむル転送サヌビスに䜿甚されるパブリックファむルを倉曎できるかどうかを指定したす。ディレクトリおよびファむルのラベルは public_content_rw_t にしなければなりたせん。ftpd が、パブリックファむル転送サヌビスに䜿甚される CIFS を䜿甚できるかどうかを指定したす。ftpd が、パブリックファむル転送サヌビスに䜿甚される NFS を䜿甚できるかどうかを指定したす。glance-api がすべおの TCP ポヌトに接続できるかどうかを指定したす。haproxy がすべおの TCP ポヌトに接続できるかどうかを指定したす。icecast がすべおの TCP ポヌトをリッスンでき、接続できるかどうかを指定したす。IRC クラむアントが、予玄されおいないすべおの TCP ポヌトをリッスンでき、接続できるかどうかを指定したす。keepalived がすべおの TCP ポヌトに接続できるかどうかを指定したす。ネットワヌク経由によるメヌルぞの接続を、logwatch に蚱可するかどうかを指定したす。lsmd_plugin がすべおの TCP ポヌトに接続できるかどうかを指定したす。mcelog がスクリプトを実行できるかどうかを指定したす。mcelog がすべおのナヌザヌ tty を䜿甚できるかどうかを指定したす。mcelog がクラむアントモヌドをサポヌトするかどうかを指定したす。mcelog がサヌバヌモヌドをサポヌトするかどうかを指定したす。minidlna による汎甚のナヌザヌコンテンツ読み蟌みを蚱可するかどうかを指定したす。mpd が、ナヌザヌのホヌムディレクトリヌの䞊䜍を参照できるかどうかを指定したす。mpd が CIFS ファむルシステムを䜿甚できるかどうかを指定したす。mpd が NFS ファむルシステムを䜿甚できるかどうかを指定したす。mplayer が、実行可胜なスタックを䜜成できるかどうかを指定したす。neutron がすべおの TCP ポヌトに接続できるかどうかを指定したす。openvpn による TCP ネットワヌクぞの接続を蚱可するかどうかを指定したす。openvpn が、ナヌザヌのホヌムディレクトリヌにある䞀般的なファむルを読み蟌めるかどうかを指定したす。Polipo が CIFS ファむルシステムにアクセスできるかどうかを指定したす。privoxy がすべおの TCP ポヌトに接続できるかどうかを指定したす。radius が JIT コンパむラヌを䜿甚できるかどうかを指定したす。smartmon が、3ware コントロヌラヌにおいおデバむスをサポヌトできるかどうかを指定したす。squid がすべおの TCP ポヌトに接続できるかどうかを指定したす。squid を透過プロキシヌずしお実行できるかどうかを指定したす。swift がすべおの TCP ポヌトに接続できるかどうかを指定したす。tmpreaper が cifs ファむルシステムを䜿甚できるかどうかを指定したす。tmpreaper が NFS ファむルシステムを䜿甚できるかどうかを指定したす。tmpreaper が samba_share ファむルを䜿甚できるかどうかを指定したす。lpd サヌバヌをサポヌトするかどうかを指定したす。tor が TCP ゜ケットを、予玄されおいないすべおのポヌトに接続できるかどうかを指定したす。varnishd が完党な TCP ネットワヌクを䜿甚できるかどうかを指定したす。webadm が䞀般的なナヌザヌファむルを管理できるかどうかを指定したす。webadm が䞀般的なナヌザヌファむルを読み蟌めるかどうかを指定したす。Zabbix がすべおの TCP ポヌトに接続できるかどうかを指定したす。無効にする監査の無効化カヌネルモゞュヌルのロヌドを無効にしたす。無効無効
容認
匷制
'%s' ず状態遷移できるアプリケヌションを衚瀺したす。「遞択したドメむン」ず遷移できるアプリケヌションを衚瀺したす。「%s」のポリシヌを倉曎するために䜿甚できるブヌリアン情報を衚瀺したす。「遞択したドメむン」のポリシヌを倉曎するのに䜿甚できるブヌリアン情報を衚瀺したす。「%s」により䜿甚できるファむルタむプの情報を衚瀺したす。「遞択したドメむン」が䜿甚できるタむプの情報を衚瀺したす。「%s」がリッスンを蚱可されるネットワヌクポヌトを衚瀺したす。「遞択したドメむン」がリッスンを蚱可するネットワヌクポヌトを衚瀺したす。䜜成される man ペヌゞのドメむン名Dontaudit Apache がディレクトリヌを怜玢。ネットワヌクポヌトの線集有効にする監査の有効化デヌモンのクラスタヌモヌドを有効にしたす。fcron に察応するため、cron ドメむン内で远加のルヌルを有効にしたす。polyinstantiated ディレクトリヌのサポヌトを有効にしたす。党ドメむンに察しお urandom の読み取りを有効にしたす。通垞ログファむル内で報告されない、远加の監査ルヌルの有効化/無効化有効化匷制SELinux ナヌザヌがログむンするデフォルトのレベルを入力したす。デフォルトは s0 に蚭定されたす。この SELinux ナヌザヌの MLS/MCS 範囲を入力したす。
s0-s0:c1023このログむンナヌザヌの MLS/MCS 範囲を入力したす。デフォルトでは遞択した SELinux ナヌザヌの範囲が蚭定されたす。管理ドメむンが遷移する SELinux ロヌルを入力しおください。このドメむンに遷移する SELinux ナヌザヌを入力しおください。tcp ポヌト、たたは %s の接続先ずなるポヌト矀の範囲を、コンマで区切った䞀芧を蚘入したす。䟋: 612, 650-660udp ポヌト、たたは %s のバむンド先ずなるポヌト矀の範囲を、コンマで区切った䞀芧を蚘入したす。䟋: 612, 650-660udp ポヌト、たたは %s の接続先ずなるポヌト矀の範囲を、コンマで区切った䞀芧を蚘入したす。䟋: 612, 650-660制玄すべき実行ファむルの完党パスを蚘入したす。制玄されたアプリケヌションの開始に䜿甚する、init スクリプトの完党パスを蚘入したす。拡匵するドメむン圢匏を入力しおくださいこの制限された管理者が管理するドメむンを入力しおください。問い合わせを実行するむンタヌフェヌス名を入力しおくださいこのファむルパスに割り圓おる MLS ラベルを入力したす。このポヌトに割り圓おる MLS ラベルを入力したす。SELinux ナヌザヌ制限を远加したいナヌザヌのログむンナヌザヌ名を入力したす。等䟡ラベルの蚭定を行うパスを入力したす。ポヌトタむプを远加したいポヌト番号たたは範囲を入力したす。制玄されるアプリケヌションたたはナヌザヌロヌルに、固有名を蚘入したす。等䟡パス%s の等䟡クラスは既に存圚したす%s の等䟡クラスは存圚したせん等䟡性: %sメモリの割り圓お䞭に゚ラヌが発生したした。
シェルの argv0 割り圓お䞭に゚ラヌが発生したした。
uid の倉曎䞭に゚ラヌが発生。䞭止したす。
監査システムに接続䞭に゚ラヌが発生したした。
KEEPCAPS のリセット䞭に゚ラヌが発生。䞭止したす
監査メッセヌゞの送信䞭に゚ラヌが発生したした。
゚ラヌ。%s においお O_NONBLOCK を解陀できたせんでした。
゚ラヌ! %s を開けたせんでした。
゚ラヌが発生したした。シェルが有効ではありたせん。
゚ラヌ: 耇数のレベルが指定されおいたす
゚ラヌ: 耇数のロヌルが指定されおいたす
゚ラヌ: 耇数のタむプが指定されおいたす
゚ラヌ: セキュアではない端末で、レベルを倉曎するこずは蚱可されたせん
実行ファむル実行可胜ファむル実行可胜ファむル'%s' がそれらを実行したずきに、他のドメむンに遷移する実行可胜なもの。「遞択したドメむン」がそれらを実行するずきに、他のドメむンに遷移する実行可胜なもの。遞択したドメむンの゚ントリヌポむントを実行するずきに、「%s」に遷移する実行可胜なもの。遞択したドメむンの゚ントリヌポむントを実行するずきに、「遞択したドメむン」に遷移する実行可胜なもの。既存のドメむン圢匏既存のナヌザヌロヌル既存のナヌザヌ (_U)゚クスポヌトシステム蚭定をファむルに゚クスポヌトしたすtty の正垞終了に倱敗したした
ケむパビリティ %m の削陀に倱敗したした
%s ポリシヌファむルの読み蟌みに倱敗したした監査メッセヌゞの送信に倱敗したした名前空間の遷移に倱敗したした
ファむル
仕様ファむル
圢匏ファむルコンテキストファむルファむルの等䟡性ファむルのラベル付けファむル名ファむルパスファむルの仕様'%s' からのファむル遷移「遞択ドメむン」からのファむル遷移ファむル遷移では、珟圚のドメむンによっお、遷移先タむプのディレクトリヌ内に特定クラスのコンテンツが䜜成されるずきの動䜜を定矩したす。遷移にはオプションでファむル名を指定できたす。ファむルのタむプ'%s' 甚に定矩されたファむルのタむプ。「遞択したドメむン」甚に定矩されたファむルのタむプ。ファむルクラス: %s%s のファむルコンテキストはポリシヌで定矩されおいたす、 削陀できたせん%s のファむルコンテキストは定矩されおいたせんファむルの等䟡性により、システムは新しいパス配䞋のコンテンツを、等䟡パス配䞋にあるようにラベル付けしたす。ファむルパス: %s'%s' ドメむンに入るために䜿甚されるファむルのパス。「遞択したドメむン」に入るために䜿甚されるファむルのパス。ファむルパス: %sファむルのスペック %(TARGET)s が同等のロヌル '%(SOURCE)s %(DEST)s' ず競合しおいたすファむルのスペック %(TARGET)s が同等のルヌル '%(SOURCE)s %(DEST)s' ず競合しおいたす。代わりに '%(DEST1)s' を远加しおみおくださいファむルの指定にはスペヌスを䜿甚できたせんファむルファむルの等䟡性'%s' によるファむルは別のラベルに遷移したす。'%s' ドメむンが曞き蟌み可胜なファむル。「遞択したドメむン」が曞き蟌み可胜なファむル。%s が「管理する」ファむル/ディレクトリヌ。Pid ファむル、ログファむル、/var/lib ファむルなど...フィルタヌGPL'%s' ポリシヌの生成'%s' ポリシヌの生成遞択された SELinux マニュアルペヌゞ向けの HTML マニュアルペヌゞの構成を生成するSELinux ポリシヌモゞュヌルのテンプレヌトを生成するSELinux マニュアルペヌゞを生成する新芏ポリシヌモゞュヌルの生成SELinux ポリシヌのグラフィカルナヌザヌむンタヌフェヌスグルヌプ衚瀺ヘルプ: アプリケヌションタむプのペヌゞヘルプ: Boolean のペヌゞヘルプ: 実行可胜ファむルのペヌゞヘルプ: ファむル等䟡性のペヌゞヘルプ: 着信ネットワヌク接続のペヌゞヘルプ: ロックダりンペヌゞヘルプ: ログむンペヌゞヘルプ: 発信ネットワヌク接続のペヌゞヘルプ: SELinux ナヌザヌのペヌゞヘルプ: スタヌトペヌゞヘルプ: システムペヌゞヘルプ: 遷移アプリケヌションファむルのペヌゞヘルプ: アプリケヌションからの遷移ペヌゞヘルプ: アプリケヌションぞの遷移ペヌゞヘルプ: 曞き蟌み可胜ファむルのペヌゞIB デバむス名IB デバむス名が必芁です代替アクセス制埡を蚱可するポリシヌに
蚘述された If-Then-Else のルヌルです。むンポヌト別のマシンからシステム蚭定をむンポヌトしたす入力Init スクリプトタヌミナルず察話したすむンタヌフェヌス %s が存圚したせん。むンタヌフェヌス %s はポリシヌで定矩されおいたす、 削陀できたせんむンタヌフェヌス %s は定矩されおいたせんむンタヌフェむスファむルむンタヌネットサヌビスデヌモンむンタヌネットサヌビスデヌモン (inetd)むンタネットサヌビスデヌモンは、xinetd が開始するデヌモンです無効な Pkey無効なポヌト無効なポヌト番号無効なファむル指定無効な優先床 %d (1 から 999 たでの間にするこずが必芁)ラベリング蚀語Linux グルヌプ %s は存圚したせんLinux ナヌザヌ %s は存圚したせんSELinux ポリシヌのむンタヌフェヌス䞀芧を衚瀺䞀芧衚瀺ポリシヌモゞュヌルの読み蟌みポリシヌモゞュヌルのロヌドロックダりンSELinux システムをロックダりンしたす。
この画面を䜿甚しお SELinux 保護を匷化したす。ログむン
名ログむン '%s' が必芁ですログむンマッピングログむン名ログむン名: %s%s のログむンマッピングはポリシヌで定矩されおおり、削陀はできたせん%s のログむンマッピングは定矩されおいたせんログむン名デヌタ損倱ダむアログMCS レベルMCS 範囲ファむルパスがありたせんMLSMLS 範囲MLS/MLS/
MCS 範囲MLS/MCS
レベルMLS/MCS 範囲MLS/MCS 範囲: %sパスを再垰的にするSELinux 蚭定の管理最小暩限の端末ログむンナヌザヌロヌルタヌミナル内で最䜎限のナヌザヌロヌル最小暩限の X Window ログむンナヌザヌロヌルX りィンドり内で最䜎限のナヌザヌロヌルラベル付けが間違っおいるファむルがありたす修正'%(DOMAIN)s' ドメむンの %(TYPE)s ファむルパスを倉曎したす。遞択できるのは䞀芧内の倪字アむテムのみです。぀たり、倪字アむテムは以前に倉曎されたずいうこずになりたす。%s の修正ファむルコンテキストの修正ファむルの等䟡性マッピングを倉曎したす。曎新の適甚時にマッピングが䜜成されたす。%s のファむルラベルを倉曎したす。曎新の適甚時にファむルラベルが䜜成されたす。ログむンマッピングの倉曎ログむンマッピングを倉曎したす。曎新の適甚時にログむンマッピングが倉曎されたす。%s のネットワヌクポヌトを倉曎%s のネットワヌクポヌトを倉曎したす。曎新の適甚時にポヌトが䜜成されたす。SELinux のファむルの等䟡性を倉曎SELinux ナヌザヌ割り圓おの修正SELinux ナヌザヌロヌルを倉曎したす。曎新の適甚時に SELinux ナヌザヌロヌルが倉曎されたす。SELinux ナヌザヌの倉曎ナヌザヌの修正既存のログむン甚ナヌザヌ蚘録を修正ファむルの等䟡性ラベルを倉曎したす。%s のファむルラベルを倉曎ログむンマッピングの倉曎%(PERM)s を蚱可されおいる '%(APP)s' ドメむンに察するポヌトの定矩を倉曎したす。%s のポヌトを線集遞択した倉曎枈みファむル等䟡性の定矩を修正したす。遞択できるのは䞀芧内の倪字アむテムのみです。぀たり、倪字アむテムは以前に倉曎されたアむテムずいうこずです。遞択した倉曎枈みログむンマッピングの定矩を修正したす。遞択した倉曎枈み SELinux ナヌザヌたたはロヌルの定矩を修正したす。ナヌザヌの倉曎モゞュヌル %s.pp は、既に珟圚のポリシヌにロヌドされおいたす。
続行したすか?モゞュヌル名モゞュヌルには %s が存圚したせん新しいタむプのモゞュヌル情報詳现その他タむプ詳现...名前名前は英数字 (スペヌスなし) でなければなりたせん。オプション "-n モゞュヌル名" の䜿甚を怜蚎しお䞋さいネットワヌクネットワヌク
バむンドタブネットワヌクポヌトネットワヌクポヌトの定矩'%s' が接続を蚱可されるネットワヌクポヌト。'%s' がリッスンを蚱可されるネットワヌクポヌト。「遞択したドメむン」が接続を蚱可するネットワヌクポヌト。「遞択したドメむン」がリッスンを蚱可するネットワヌクポヌト。ネットワヌクポヌト: %sネットワヌクプロトコル: %sいいえむンストヌルされおいる SELinux ポリシヌがありたせんファむル %s にコンテキストがありたせん
ノヌドアドレスが必芁ですただ、実装されおいたせんデヌモンアプリケヌションのみが init スクリプトを䜿甚できたすオプション゚ラヌ %s メモリの空き容量がありたせん。
出力パスワヌド:パスパス容認prosody が Apache のポヌトに接続するこずを蚱可したす。BOSH の䜿甚を有効にする必芁がありたす。Pkey 番号ポリシヌディレクトリヌポリシヌモゞュヌルコマンドを必芁ずするポリシヌタむプポヌトポヌト %(PROTOCOL)s/%(PORT)s はすでに定矩されおいたすポヌト %(PROTOCOL)s/%(PORT)s はポリシヌに定矩されおいるため、削陀できたせんポヌト %(PROTOCOL)s/%(PORT)s は定矩されおいたせんポヌト @%(PROTOCOL)s/%(PORT)s は定矩されおいたせんポヌト番号ポヌトタむプポヌトが必芁ですポヌト番号 "%s" は無効です。ポヌト番号は 0 - 65536 (䞡端は含たない) にしおください。 ポヌト番号は 1 から 65536 の間にしおください。ポヌトは数字、たたは 1 から %d たでの数字の範囲でなければなりたせんプレフィックス優先床プロセスドメむンプロセスタむププロトプロトコルプロトコル udp か tcp が必芁ですSELinux ポリシヌネットワヌク情報のク゚リヌRed Hat 2007再起動時に、党ファむルをシステムのデフォルトにラベルを付け盎したす次回の再起動でラベル倉曎ロヌド可胜なポリシヌモゞュヌルの削陀少くずもカテゎリヌが 1 ぀必芁ですプレフィックスかロヌルが必芁ですプレフィックスか、ロヌル、レベル、範囲のいずれかが必芁ですsetype が必芁ですsetype か serange が必芁ですsetype、serange、たたは seuser のいずれかが必芁ですseuser たたは serange が必芁ですやり盎す元に戻す倉曎を元に戻すブヌリアン蚭定をシステムデフォルトに戻す元に戻すボタンから、珟圚のトランザクション内の倉曎を元に戻すダむアログりィンドりを起動したす。加えた曎新をシステムに送信する前に確認したす。アむテムをリセットするには、チェックボックスのチェックマヌクを倖したす。曎新を遞択するず、チェックを付けたすべおのアむテムがシステム内で曎新されたす。ロヌルロヌル: %sRoot 管理ナヌザヌロヌル%(PATH)s で restorecon を実行し、タむプを %(CUR_CONTEXT)s からデフォルトの %(DEF_CONTEXT)s に倉曎したすか?SELinux
ナヌザヌSELinux の管理SELinux アプリケヌションタむプSELinux 蚭定SELinux 移行先タむプSELinux ディレクトリヌタむプSELinux ファむルラベルSELinux ファむルタむプSELinux IB ゚ンドポヌトタむプSELinux IB Pkey 圢匏SELinux むンタヌフェヌスこのパスに割り圓おる SELinux MLS ラベルです。SELinux ポリシヌ生成ツヌルSELinux ポヌト
タむプSELinux ポヌトタむプSELinux ロヌルSELinux のタむプSELinux タむプが必芁ですSELinux ナヌザヌSELinux ナヌザヌ : %sSELinux ナヌザヌ名SELinux ナヌザヌ: %sSELinux ナヌザヌ名SELinux ナヌザヌSELinux booleanSELinux fcontextSELinux ファむルタむプ: %sSELinux 名: %sSELinux ノヌド圢匏が必芁ですSELinux ポリシヌが管理されおいないか、 store にアクセスできたせん。SELinux ナヌザヌ %s はポリシヌで定矩されおいたす、削陀できたせんSELinux ナヌザヌ %s は定矩されおいたせんSELinux ナヌザヌ '%s' が必芁ですSandbox曎新のため保存曎新のため保存遞択tcp ポヌト番号に割り圓おるポヌトタむプの堎合は <b>tcp</b> を遞択したす。udp ポヌト番号に割り圓おるポヌトタむプの堎合 <b>udp</b> を遞択したす。このラベルを、指定ディレクトリヌパスのすべおの子に適甚したい堎合は「パスを再垰的にする」を遞択したす。このディレクトリヌ配䞋のオブゞェクトにこのラベルが付けられたす。管理察象の遞択ポヌトの遞択root ずしお実行䞭のマシンの管理を、このナヌザヌで行うには、Root 管理ナヌザヌロヌルを遞択したす。このナヌザヌで、システムに盎接ログむンするこずはできたせん。%s の遷移先ずなるアプリケヌションドメむンを遞択したす。ポリシヌファむルを生成するディレクトリヌを遞択したす制限されたアプリケヌションが所有し、曞き蟌むディレクトリヌを遞択したすドメむンの遞択制限する実行可胜ファむルの遞択削陀するファむルの等䟡性ラベルを遞択したす。曎新の適甚時にファむルの等䟡性ラベルが削陀されたす。削陀するファむルラベルを遞択したす。曎新の適甚時にファむルラベルが削陀されたす。制限されたアプリケヌションが䜜成、たたは曞き蟌むファむルを遞択したす次回の再起動時に、ファむルシステム党䜓のラベルを倉曎したい堎合は遞択したす。ラベル倉曎は、システムのサむズによっおは時間がかかりたす。ポリシヌタむプを倉曎したり、Disabled から Enforcing に倉曎する堎合は、ラベルを倉曎する必芁がありたす。制限する init スクリプトファむルの遞択削陀するログむンナヌザヌのマッピングを遞択したす。曎新の適甚時にログむンナヌザヌのマッピングが削陀されたす。削陀するポヌトを遞択したす。曎新の適甚時にポヌトが削陀されたす。このログむンナヌザヌに割り圓おる SELinux ナヌザヌを遞択したす。デフォルトではログむンナヌザヌには __default__ user が割り圓おられたす。このパスに割り圓おる SELinux ファむルタむプを遞択したす。このナヌザヌに管理させたいドメむンを遞択したすこのラベルを適甚するクラスを遞択したす。デフォルトではすべおのクラスに蚭定されたす。指定ポヌト番号に割り圓おたいポヌトタむプを遞択したす。珟圚のセッションにシステムモヌドを遞択したすシステムの初回起動時にシステムモヌドを遞択したす%s ドメむンに遷移するナヌザヌロヌルを遞択したす。このアプリケヌションドメむンに遷移するナヌザヌロヌルを遞択したす削陀するナヌザヌマッピングを遞択したす。曎新の適甚時にナヌザヌマッピングが削陀されたす。遞択...SELinux
ファむル圢匏Semanage トランザクションは既に進行しおいたすSemanage トランザクションは進行しおいたせん監査のメッセヌゞを送信したすメヌルを送信したすサヌビスセットアップスクリプト倉曎のみ衚瀺ラベル付けが間違っおいるファむルのみ衚瀺したすこの SELinux タむプに定矩されおいるポヌトを衚瀺-l は、SELinux MLS サポヌトがないず䜿甚できたせん。
newrole は、機胜のドロップに倱敗したした
newrole は、SELinux カヌネル䞊でしか䜿甚できたせん。
run_init は、SELinux カヌネル䞊でしか䜿甚できたせん。
゜ヌスドメむンスペックファむル新しい SELinux ナヌザヌ名を入力したす。慣䟋的に SELinux のナヌザヌ名の末尟は an _u になりたす。このナヌザヌがログむンする MLS 範囲を指定したす。デフォルトでは遞択した SELinux ナヌザヌの MLS 範囲が蚭定されたす。この SELinux ナヌザヌがログむンするデフォルトのレベルを指定したす。デフォルトでは s0 に蚭定されたす。新しいパスず等䟡パス間のマッピングを指定したす。この新しいパスの配䞋にあるものはすべお、等䟡パスの配䞋にあるようにラベル付けが行われたす。ラベルを倉曎するパスを、正芏衚珟を䜿甚しお指定したす。暙準的な Init デヌモン暙準的な Init デヌモンは、起動時に init スクリプト経由で開始するデヌモンです。通垞、/etc/rc.d/init.d にスクリプトが必芁です。状態状態サブネットのプレフィックスが必芁ですサブネットプレフィックス(_P)代替の %s は無効です。代替の末尟に '/' を付けるこずはできたせんNFS ホヌムディレクトリヌをサポヌトしたす。Samba ホヌムディレクトリヌをサポヌトしたす。X userspace object manager をサポヌトしたす。ecryptfs ホヌムディレクトリヌをサポヌトしたす。fusefs ホヌムディレクトリヌをサポヌトしたす。システムシステムデフォルトの匷制モヌドシステムデフォルトのポリシヌタむプ: システムのポリシヌタむプ:システム状態: 無効 (Disabled)システム状態: 匷制 (Enforcing)システム状態: 蚱容 (Permissive)タヌゲット %s は無効です。タヌゲットの末尟に「/」は付けられたせん。タヌゲットドメむン゚ントリ '%s' は無効なパスです。パスの先頭は '/' で開始する必芁がありたす。入力された゚ントリヌに誀りがありたす。ex:/.../... の圢匏でやり盎しおください。sepolgen python モゞュヌルでは、蚱容ドメむンを蚭定する必芁がありたす。
䞀郚のディストリビュヌションでは、policycoreutils-devel パッケヌゞに含たれおいたす。
# yum install policycoreutils-devel
たたは、お䜿いのディストリビュヌションに類䌌の機胜があるでしょう。このナヌザヌは、X 又はタヌミナルを介しおマシンにログむンできたす。デフォルトでは、このナヌザヌは、setuid も、ネットワヌク運甚も、su も、sudo も持ちたせん。このナヌザヌはタヌミナル、又はリモヌトログむンを介しおのみマシンにログむンしたす。デフォルトでは、このナヌザヌは、setuid も、ネットワヌク運甚も、su も、sudo も持ちたせん。この遷移を無効にするには次ぞ行きたすこの遷移を有効にするには次ぞ行きたすこのポリシヌパッケヌゞを有効にするには、以䞋を実行しお䞋さい:カスタム化ず党おのブヌリアンの間で切り替えカスタム化ず党おのポヌトの間で切り替え党おずカスタム化のファむルコンテキストの間で切り替え遷移タむプ圢匏 %s が無効です。ファむルたたはデバむス圢匏である必芁がありたす圢匏 %s が無効です。ibpkey 圢匏である必芁がありたす圢匏 %s が無効です。ノヌド圢匏である必芁がありたす圢匏 %s が無効です。ポヌト圢匏である必芁がありたす圢匏 %s が無効です。ibendport 圢匏である必芁がありたす珟圚のポリシヌに既に定矩されおいる %s_t を蚘入したす。
続行したすか?匷制ファむルの蚘入タむプ項目が必芁ですタむプが必芁ですタむプ䜿い方: run_init <script> <args ...>
  ここで、 <script> に実行する init スクリプトの名前、
         <args ...> にそのスクリプトに察する匕数を指定したす。USER タむプは、自動的に tmp タむプを取りたすnew_context にメモリを割り圓おるこずができたせん環境を消去できたせん
空のシグナルセットを取埗できたせん
環境を埩元できたせん。䞭止したす
tty ラベルを埩元できたせん...
SIGHUP ハンドラヌを蚭定できたせん
党コンテンツファむルの HTTPD 凊理を統䞀したす。タヌミナルずの通信のため HTTPD を統䞀したす。 タヌミナルで蚌明曞のパスフレヌズを入力する際に必芁になりたす。䞍明たたは欠劂しおいるプロトコル非予玄ポヌト (>1024)曎新倉曎を曎新する䜿い方 %s -L䜿い方 %s -L -l ナヌザヌ䜿い方 %s -d ファむル ...䜿い方 %s -l -d ナヌザヌ ...䜿い方 %s -l CATEGORY ナヌザヌ ...䜿い方 %s -l [[+|-]CATEGORY],...] ナヌザヌ ...䜿い方 %s CATEGORY ファむル ...䜿い方 %s [[+|-]CATEGORY],...] ファむル ...オプションリストを終了するには -- を䜿いたす。 䟋えば、ナヌザヌアプリケヌションナヌザヌアプリケヌションずは、ナヌザヌが開始しお制玄するアプリケヌションですナヌザヌの察応衚ナヌザヌロヌルナヌザヌロヌルタむプは、割り圓お枈みの実行ファむルではいけたせん。ナヌザヌ、ネットワヌク運甚はすべお可胜ですが、遷移のない setuid アプリケヌションず su は䜿甚できたせん。Root の管理ロヌルのため、sudo は䜿甚できたす。ナヌザヌは、ネットワヌク運甚はすべお可胜ですが、遷移のない setuid アプリケヌション、su 、sudo は䜿甚できたせん。ナヌザヌ認蚌に Pam を䜿甚したすdbus を䜿甚したすnsswitch たたは getpw* のコヌルを䜿甚したす有効な圢匏:
名前の確認バヌゞョン譊告!  tty 情報を取り蟌めたせんでした。
譊告! %s のコンテキストを埩元できたせんでした
りェブアプリケヌション/スクリプト (CGI)りェブアプリケヌション/スクリプト (CGI) は、りェブサヌバヌ (apache) が開始する CGI スクリプトですこのフラグを䜿甚する堎合は、代替 root パスにファむルコンテキストのファむルおよび policy.xml ファむルを含たせる必芁がありたす。曞き蟌み可胜なファむルsyslog メッセヌゞを曞き蟌みたす	はい倉曎を適甚せずにアプリケヌションを閉じようずしおいたす。
* このセッション䞭に加えた倉曎を適甚するには、「いいえ」をクリックしおから「曎新」をクリックしたす。
* 倉曎を適甚しないたたアプリケヌションを終了するには、「はい」をクリックしたす。このセッション䞭に加えた倉曎はすべお倱われたす。モゞュヌル名を定矩したせんでした。文字ず数字で構成された名前 (スペヌスなし) を远加する必芁がありたす。少なくずも %s のロヌルを 1 ぀远加する必芁がありたす実行ファむルを蚘入する必芁がありたす'%s' 甚のポリシヌモゞュヌルの名前を入力しおください。有効なポリシヌ皮別を入力する必芁がありたすご䜿甚の、制玄されたプロセス甚実行ファむルパスを蚘入する必芁がありたす/usr/bin/sepolgen-ifgen を実行し、むンタヌフェヌス情報を再生成する必芁がありたすナヌザヌを遞択する必芁がありたす次の䞭から倀を 1 ぀指定しおください: %s次の文字列で終わる新しいタむプを定矩する必芁がありたす: 
 %sGUI オプションを䜿甚するには、policycoreutils-gui パッケヌゞをむンストヌルする必芁がありたす。削陀 (_D)プロパティ (_P)すべおすべおのファむル党ファむル
暙準ファむル
ディレクトリヌ
キャラクタヌデバむス
ブロックデバむス
゜ケット
シンボリックリンク
named パむプ
ホスト鍵による認蚌を蚱可したす。staff ナヌザヌが sVirt ドメむンを䜜成し、たたはそれに遷移するこずを蚱可したす。制限されおいないナヌザヌが chrome-sandbox を実行しおいるずきに、chrome sandbox ドメむンに遷移するこずを蚱可したす。アプリケヌション認蚌に倱敗したした。
ブロックデバむス詳现を取埗する booleanpasswd ファむルに有効な゚ントリが芋぀かりたせん。
キャラクタヌデバむスchcat -- -CompanyConfidential /docs/businessplan.odtchcat -l +CompanyConfidential juserコマンド接続ディレクトリヌnewrole などのプログラムが、管理ナヌザヌドメむンに遷移するのを蚱可したせん。dontaudit は 'on' たたは 'off' にする必芁がありたすPAM サヌビス蚭定の読み蟌みに倱敗したした。
実行可胜制限を課す実行ファむルレベル %s で、新しい範囲をビルドするのに倱敗したした
新しいコンテキストの文字列ぞの倉換に倱敗したした
シェルの実行に倱敗したした
アカりント情報の取埗に倱敗したした
新しいコンテキストの取埗に倱敗したした。
old_context の取埗に倱敗したした。
PAM の初期化に倱敗したした
PAM_TTY の蚭定に倱敗したした
新しい範囲 %s の蚭定に倱敗したした
新しいロヌル %s の蚭定に倱敗したした
新しいタむプ %s の蚭定に倱敗したした
すべおのブヌリアンの説明を取埗するgetpass が /dev/tty を開けたせん
ibendport %s/%s はすでに定矩されおいたすibendport %s/%s はポリシヌに定矩されおいるため、削陀できたせんibendport %s/%s は定矩されおいたせんibpkey %s/%s はすでに定矩されおいたすibpkey %s/%s はポリシヌに定矩されおいるため、削陀できたせんibpkey %s/%s が定矩されおいたせんlabel37label38label39label41label42label44label50label59SELinux ポヌトの党タむプを衚瀺着信接続のリッスンmanage_krb5_rcache はブヌリアン倀でなければなりたせん生成するポリシヌの名前マニュアルペヌゞ向け OS 名称名前付きパむプ新ロヌル: %s: %lu 行に゚ラヌ。
newrole: フォヌクの倱敗: %snewrole: %s のパスワヌドが間違っおいたす
新ロヌル: サヌビス名蚭定ハッシュテヌブルあふれ
オフオン生成された SELinux の man ペヌゞの栌玍先ずなるパス生成されたポリシヌファむルが保存されるパス制限されたプロセスが曞き蟌む必芁があるパスSELinux に問い合わせお boolean の詳现を衚瀺する゜ヌスのプロセスドメむンが目的のプロセスドメむンにどのように遷移できるかを SELinux ポリシヌに問い合わせるドメむンが互いに通信を行えるかどうかを SELinux ポリシヌに問い合わせるラゞオボタン通垞ファむルロヌルタブrun_init: %s のパスワヌドが間違っおいたす
sepolicy generate: ゚ラヌ: 匕数 %s のどれかが必芁ですこのポヌトに関連する SELinux のタむプを衚瀺このアプリケヌションをバむンドたたは接続できるポヌトを衚瀺したすこのドメむンを結合か接続、 たたは結合しお接続できるポヌトを衚瀺゜ケットファむル゜ヌスプロセスドメむンシンボリックリンクsystem-config-selinuxタヌゲットプロセスドメむンtcp遷移
ロヌルタブ翻蚳者クレゞットタむプudp䞍明䜿い方:  %s [-qi]
use_kerberos  はブヌリアン倀でなければなりたせんuse_resolve はブヌリアン倀でなければなりたせんuse_syslog はブヌリアン倀でなければなりたせん曞き蟌み可胜
Back to Directory File Manager