define(`can_kerberos',`
ifdef(`kerberos.te',`
if (allow_kerberos) {
can_network_client($1, `kerberos_port_t')
can_resolve($1)
}
') dnl kerberos.te
dontaudit $1 krb5_conf_t:file write;
allow $1 krb5_conf_t:file { getattr read };
')