selinux/policycoreutils/semanage/semanage-dontaudit.8
Dan Walsh 1925e1e91d Break the semanage man page into different man pages per category.
This adds a lot of new man pages but cleans up the descriptions and makes it
much easier to handle.
2013-10-24 13:58:40 -04:00

35 lines
1.2 KiB
Groff

.TH "semanage-dontaudit" "8" "20130617" "" ""
.SH "NAME"
.B semanage dontaudit\- SELinux Policy Management dontaudit tool
.SH "SYNOPSIS"
.B semanage dontaudit [\-h] [\-S STORE] [\-N] {on,off}
.SH "DESCRIPTION"
semanage is used to configure certain elements of
SELinux policy without requiring modification to or recompilation
from policy sources. semanage dontaudit toggles whether or not dontaudit rules will be in the policy. Policy writers use dontaudit rules to cause
confined applications to use alternative paths. Dontaudit rules are denied but not reported in the logs. Some times dontaudit rules can cause bugs in applications but policy writers will not relize it since the AVC is not audited. Turning off dontaudit rules with this command to see if the kernel is blocking an access.
.SH "OPTIONS"
.TP
.I \-h, \-\-help
show this help message and exit
.TP
.I \-S STORE, \-\-store STORE
Select an alternate SELinux Policy Store to manage
.TP
.I \-N, \-\-noreload
Do not reload the policy after commit
.SH EXAMPLE
.nf
Turn off dontaudit rules
# semanage dontaudit off
.SH "SEE ALSO"
.B selinux (8),
.B semanage (8)
.SH "AUTHOR"
This man page was written by Daniel Walsh <dwalsh@redhat.com>