SELinux: Difference between revisions

From Leo's Notes
This page was last edited on 9 February 2014, at 20:00.
No edit summary
No edit summary
Line 4: Line 4:
* http://fedoraproject.org/wiki/SELinux/Understanding
* http://fedoraproject.org/wiki/SELinux/Understanding


== Targets ==
=== Targets ===
By default, a RHEL install has SELinux set to permissive with the default policy set to targeted. Targeted is a set of policies made by RedHat that 'targets' a set number of existing services (such as apache, bind, etc) while leaving everything else unconfined.  
By default, a RHEL install has SELinux set to permissive with the default policy set to targeted. Targeted is a set of policies made by RedHat that 'targets' a set number of existing services (such as apache, bind, etc) while leaving everything else unconfined.  


 
== Getting Started ==
== Common Tasks ==
Ensure that you have SELinux enabled. To check on SELinux's status, run <code>sestatus</code>
=== Checking on SELinux ===
Use the sestatus command:


<syntaxhighlight lang="text" line start="1" enclose="div">
<syntaxhighlight lang="text" line start="1" enclose="div">
Line 21: Line 19:
Policy from config file:        targeted
Policy from config file:        targeted
</syntaxhighlight>
</syntaxhighlight>
If your status is disabled, enable SELinux by editing <code>/etc/selinux/config</code> and change the line SELINUX=disabled to SELINUX=permissive. You do not want to set SELINUX to enforcing yet! (because your filesystem might not be labeled, which can cause your system to not boot at all).
You will also want to start the auditd daemon. By default, all SELinux messages go directly to /var/log/messages with the avc tag. With the <code>auditd</code> daemon running, log messages will go to /var/log/audit/audit.log.
You will also want to install the setroubleshoot and setroubleshoot-plugins package. This package installs the <code>sealert</code> program which makes it easier to understand any SELinux errors by generating readable reports and providing instructions on what to do to fix a particular issue.
=== Relabeling your Filesystem ===
To relabel your entire filesystem, create a <code>.autorelabel</code> file in <code>/</code> and then reboot.
== Common Tasks ==
=== Checking on SELinux ===
Use the sestatus command:





Revision as of 20:00, 9 February 2014

Introduction

Targets

By default, a RHEL install has SELinux set to permissive with the default policy set to targeted. Targeted is a set of policies made by RedHat that 'targets' a set number of existing services (such as apache, bind, etc) while leaving everything else unconfined.

Getting Started

Ensure that you have SELinux enabled. To check on SELinux's status, run sestatus

[root@websix ~]# sestatus
SELinux status:                 enabled
SELinuxfs mount:                /selinux
Current mode:                   permissive
Mode from config file:          permissive
Policy version:                 24
Policy from config file:        targeted

If your status is disabled, enable SELinux by editing /etc/selinux/config and change the line SELINUX=disabled to SELINUX=permissive. You do not want to set SELINUX to enforcing yet! (because your filesystem might not be labeled, which can cause your system to not boot at all).

You will also want to start the auditd daemon. By default, all SELinux messages go directly to /var/log/messages with the avc tag. With the auditd daemon running, log messages will go to /var/log/audit/audit.log.

You will also want to install the setroubleshoot and setroubleshoot-plugins package. This package installs the sealert program which makes it easier to understand any SELinux errors by generating readable reports and providing instructions on what to do to fix a particular issue.

Relabeling your Filesystem

To relabel your entire filesystem, create a .autorelabel file in / and then reboot.



Common Tasks

Checking on SELinux

Use the sestatus command:


Changing SELinux Mode

setenforce [ Enforcing or 1 | Permissive or 0 ]

You cannot disable SELinux using setenforce. Instead, see [#Disabling SELinux]

Listing security contexts

Use the -Z option. This works for a few utilities including:

  • ls
  • netstat
  • ps

Example:

[root@websix ~]# ls -Z
-rw-------. root root system_u:object_r:admin_home_t:s0 anaconda-ks.cfg
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log.syslog

Disabling SELinux

To temporarily disable SELinux:

echo 0 > /selinux/enforce

To permanently disable SELinux:

vi /etc/selinux/config
# ...and change to SELINUX=disabled