SELinux: Difference between revisions

From Leo's Notes
This page was last edited on 9 February 2014, at 19:38.
No edit summary
No edit summary
Line 1: Line 1:


== Introduction ==
== Introduction ==
http://wiki.eri.ucsb.edu/sysadm/SELinux
* http://wiki.eri.ucsb.edu/sysadm/SELinux
http://fedoraproject.org/wiki/SELinux/Understanding
* http://fedoraproject.org/wiki/SELinux/Understanding


== Targets ==
By default, a RHEL install has SELinux set to permissive with the default policy set to targeted. Targeted is a set of policies made by RedHat that 'targets' a set number of existing services (such as apache, bind, etc) while leaving everything else unconfined.


== Disable SELinux ==
 
== Common Tasks ==
=== Checking on SELinux ===
Use the sestatus command:
 
<syntaxhighlight lang="text" line start="1" enclose="div">
[root@websix ~]# sestatus
SELinux status:                enabled
SELinuxfs mount:                /selinux
Current mode:                  permissive
Mode from config file:          permissive
Policy version:                24
Policy from config file:        targeted
</syntaxhighlight>
 
 
=== Changing SELinux Mode ===
 
setenforce [ Enforcing or 1 | Permissive or 0 ]
 
You cannot disable SELinux using setenforce. Instead, see [#Disabling SELinux]
 
=== Listing security contexts ===
 
Use the <code>-Z</code> option. This works for a few utilities including:
* ls
* netstat
* ps
 
Example:
<syntaxhighlight lang="text" line start="1" enclose="div">
[root@websix ~]# ls -Z
-rw-------. root root system_u:object_r:admin_home_t:s0 anaconda-ks.cfg
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log.syslog
</syntaxhighlight>
 
=== Disabling SELinux ===
To temporarily disable SELinux:
To temporarily disable SELinux:



Revision as of 19:38, 9 February 2014

Introduction

Targets

By default, a RHEL install has SELinux set to permissive with the default policy set to targeted. Targeted is a set of policies made by RedHat that 'targets' a set number of existing services (such as apache, bind, etc) while leaving everything else unconfined.


Common Tasks

Checking on SELinux

Use the sestatus command:

[root@websix ~]# sestatus
SELinux status:                 enabled
SELinuxfs mount:                /selinux
Current mode:                   permissive
Mode from config file:          permissive
Policy version:                 24
Policy from config file:        targeted


Changing SELinux Mode

setenforce [ Enforcing or 1 | Permissive or 0 ]

You cannot disable SELinux using setenforce. Instead, see [#Disabling SELinux]

Listing security contexts

Use the -Z option. This works for a few utilities including:

  • ls
  • netstat
  • ps

Example:

[root@websix ~]# ls -Z
-rw-------. root root system_u:object_r:admin_home_t:s0 anaconda-ks.cfg
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log.syslog

Disabling SELinux

To temporarily disable SELinux:

echo 0 > /selinux/enforce

To permanently disable SELinux:

vi /etc/selinux/config
# ...and change to SELINUX=disabled