SELinux

From Leo's Notes
Revision as of 19:38, 9 February 2014 by Leo (talk | contribs)
This page was last edited on 9 February 2014, at 19:38.

Introduction

Targets

By default, a RHEL install has SELinux set to permissive with the default policy set to targeted. Targeted is a set of policies made by RedHat that 'targets' a set number of existing services (such as apache, bind, etc) while leaving everything else unconfined.


Common Tasks

Checking on SELinux

Use the sestatus command:

[root@websix ~]# sestatus
SELinux status:                 enabled
SELinuxfs mount:                /selinux
Current mode:                   permissive
Mode from config file:          permissive
Policy version:                 24
Policy from config file:        targeted


Changing SELinux Mode

setenforce [ Enforcing or 1 | Permissive or 0 ]

You cannot disable SELinux using setenforce. Instead, see [#Disabling SELinux]

Listing security contexts

Use the -Z option. This works for a few utilities including:

  • ls
  • netstat
  • ps

Example:

[root@websix ~]# ls -Z
-rw-------. root root system_u:object_r:admin_home_t:s0 anaconda-ks.cfg
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log
-rw-r--r--. root root system_u:object_r:admin_home_t:s0 install.log.syslog

Disabling SELinux

To temporarily disable SELinux:

echo 0 > /selinux/enforce

To permanently disable SELinux:

vi /etc/selinux/config
# ...and change to SELINUX=disabled