We are looking into adding the attached patch for apache policy. Basically it is a boolean that will eliminate the difference between the way httpd handles content. So setting unified_apache will make all content the same and fall back to DAC as far as cgi executables. This will allow easier transition to SELinux and allow relabeling of the /var/www/html directory to not stop apache from working. It will be turned on by default in targeted policy and off in strict policy. Comments? Dan