I can't find where I read this now, could somebody please tell me what I need to add/remove from the strict policy to disallow running of the setenforce command (but still allow changing enforcement mode via rebooting) ? Thanks, Todd