http://people.fedoraproject.org/~dwalsh/SELinux/F14/roles_secadm.patch Allow secadm_t to read /root files so if sysadm_t creates pp file, secadm_t can install it.