SELinux
From Leo's Notes
This page was last edited on 9 February 2014, at 19:38.
Introduction
Targets
By default, a RHEL install has SELinux set to permissive with the default policy set to targeted. Targeted is a set of policies made by RedHat that 'targets' a set number of existing services (such as apache, bind, etc) while leaving everything else unconfined.
Common Tasks
Checking on SELinux
Use the sestatus command:
[root@websix ~]# sestatus
SELinux status: enabled
SELinuxfs mount: /selinux
Current mode: permissive
Mode from config file: permissive
Policy version: 24
Policy from config file: targeted
Changing SELinux Mode
setenforce [ Enforcing or 1 | Permissive or 0 ]
You cannot disable SELinux using setenforce. Instead, see [#Disabling SELinux]
Listing security contexts
Use the -Z option. This works for a few utilities including:
- ls
- netstat
- ps
Example:
[root@websix ~]# ls -Z
-rw-------. root root system_u:object_r:admin_home_t:s0 anaconda-ks.cfg
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log.syslog
Disabling SELinux
To temporarily disable SELinux:
echo 0 > /selinux/enforce
To permanently disable SELinux:
vi /etc/selinux/config # ...and change to SELINUX=disabled