Anonymous

Not logged in

  • Log in
DWIKI

Selinux

From DWIKI

Namespaces

  • Page
  • Discussion

More

  • More

Page actions

  • Read
  • View source
  • History

Contents

  • 1 Links
  • 2 FAQ
    • 2.1 no audit2allow
    • 2.2 allow apache processes to network
    • 2.3 avc: denied { getattr }
    • 2.4 avc: denied { name_connect }
    • 2.5 temporarily disable selinux
    • 2.6 disable selinux
    • 2.7 Add allow

Links

  • https://wiki.centos.org/HowTos/SELinux
  • http://www.linuxquestions.org/questions/linux-security-4/reuse-selinux-policy-896536/
  • https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Security-Enhanced_Linux/sect-Security-Enhanced_Linux-SELinux_Contexts_Labeling_Files-Persistent_Changes_semanage_fcontext.html
  • https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Security-Enhanced_Linux/sect-Security-Enhanced_Linux-Fixing_Problems-Allowing_Access_audit2allow.html

FAQ

no audit2allow

yum install policycoreutils-python

allow apache processes to network

setsebool -P httpd_can_network_connect 1
setsebool -P httpd_can_network_connect_db 1

avc: denied { getattr }

avc: denied { name_connect }

temporarily disable selinux

 setenforce 0

disable selinux

edit /etc/selinux/config


Add allow

(probably not this brutal)

Grep AVC /var/log/audit/audit.log | audit2allow -a -M someservice
Retrieved from "https://wiki.dhits.nl/index.php?title=Selinux&oldid=5902"

Navigation

Navigation

  • Main Page
  • Community portal
  • Recent changes
  • Random page
  • Help

Wiki tools

Wiki tools

  • Special pages
  • Page values

Page tools

Page tools

    User page tools

      More

      • What links here
      • Related changes
      • Printable version
      • Permanent link
      • Page information
      • Page logs
      • Powered by MediaWiki
      • This page was last edited on 27 May 2019, at 06:56.
      • Privacy policy
      • About DWIKI
      • Disclaimers