SELinux: Difference between revisions
From Leo's Notes
This page was last edited on 9 February 2014, at 19:38.
No edit summary |
No edit summary |
||
| Line 1: | Line 1: | ||
== Introduction == | == Introduction == | ||
http://wiki.eri.ucsb.edu/sysadm/SELinux | * http://wiki.eri.ucsb.edu/sysadm/SELinux | ||
http://fedoraproject.org/wiki/SELinux/Understanding | * http://fedoraproject.org/wiki/SELinux/Understanding | ||
== Targets == | |||
By default, a RHEL install has SELinux set to permissive with the default policy set to targeted. Targeted is a set of policies made by RedHat that 'targets' a set number of existing services (such as apache, bind, etc) while leaving everything else unconfined. | |||
== | |||
== Common Tasks == | |||
=== Checking on SELinux === | |||
Use the sestatus command: | |||
<syntaxhighlight lang="text" line start="1" enclose="div"> | |||
[root@websix ~]# sestatus | |||
SELinux status: enabled | |||
SELinuxfs mount: /selinux | |||
Current mode: permissive | |||
Mode from config file: permissive | |||
Policy version: 24 | |||
Policy from config file: targeted | |||
</syntaxhighlight> | |||
=== Changing SELinux Mode === | |||
setenforce [ Enforcing or 1 | Permissive or 0 ] | |||
You cannot disable SELinux using setenforce. Instead, see [#Disabling SELinux] | |||
=== Listing security contexts === | |||
Use the <code>-Z</code> option. This works for a few utilities including: | |||
* ls | |||
* netstat | |||
* ps | |||
Example: | |||
<syntaxhighlight lang="text" line start="1" enclose="div"> | |||
[root@websix ~]# ls -Z | |||
-rw-------. root root system_u:object_r:admin_home_t:s0 anaconda-ks.cfg | |||
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log | |||
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log.syslog | |||
</syntaxhighlight> | |||
=== Disabling SELinux === | |||
To temporarily disable SELinux: | To temporarily disable SELinux: | ||
Revision as of 19:38, 9 February 2014
Introduction
Targets
By default, a RHEL install has SELinux set to permissive with the default policy set to targeted. Targeted is a set of policies made by RedHat that 'targets' a set number of existing services (such as apache, bind, etc) while leaving everything else unconfined.
Common Tasks
Checking on SELinux
Use the sestatus command:
[root@websix ~]# sestatus
SELinux status: enabled
SELinuxfs mount: /selinux
Current mode: permissive
Mode from config file: permissive
Policy version: 24
Policy from config file: targeted
Changing SELinux Mode
setenforce [ Enforcing or 1 | Permissive or 0 ]
You cannot disable SELinux using setenforce. Instead, see [#Disabling SELinux]
Listing security contexts
Use the -Z option. This works for a few utilities including:
- ls
- netstat
- ps
Example:
[root@websix ~]# ls -Z
-rw-------. root root system_u:object_r:admin_home_t:s0 anaconda-ks.cfg
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log.syslog
Disabling SELinux
To temporarily disable SELinux:
echo 0 > /selinux/enforce
To permanently disable SELinux:
vi /etc/selinux/config # ...and change to SELINUX=disabled