Master boolean index:
Global
secure_mode
(Default: false)
disallow programs, such as
newrole, from transitioning to administrative
user domains.
Module:
kernel
Layer:
kernel
secure_mode_insmod
(Default: false)
disallow programs and users from transitioning to insmod domain.
Module:
selinux
Layer:
kernel
secure_mode_policyload
(Default: false)
prevent all confined domains from loading policy, setting
enforcing mode, and changing boolean values. Set this to true and you
have to reboot to set it back