Skip to main content

SElinux is your Friend?

SElinux is much more involved than I originally had assumed. However, it should not be feared.
# sealert -a /var/log/audit/audit.log

[root@desktop9 audit]# ls -lZd /var/www/html/
drwxr-xr-x. root root system_u:object_r:httpd_sys_content_t:s0 /var/www/html/

user : role : type : sens : cat

# audit2allow
Command to convert audit log to policy updates to allow the tasks that were previously denied.

append { selinux | enforcing } = 0 on the kernel line in grub

IF... you happen to disable and re-enable SElinux, it will require a "relabel -RF" of the entire filesystem.

I'm actually becoming enamored with SElinux... seriously cool stuff.

To update your context, you should use
# semanage fcontext -a
and not just chcon. If you happen to do a restorecon using chcon, it will revert the content back to it's original intended context.

# man -k selinux
# man -k _selinux
-- Check out this location
# /etc/selinux/targeted/contexts/files

# gesebool -a
# semanage boolean -l

-- Prep work - copy a directory to /var/www/html and attempt to access it.
# tail /var/log/messages (look for the UUID to review)
# sealert -l a19fa6d0-90d6-4c8c-8d2f-d964d77a5965
# /sbin/restorecon '/var/www/html/web_content/index.html' (fixes the one file)
# semanage fcontext -a -f "" -t httpd_sys_content_t '/var/www/html/web_content/*' (adds context)
# restorecon -RFvv /var/www/html/web_content/ (fixes the entire directory)


< THIS PAGE NEEDS UPDATES >

Comments

Popular posts from this blog

PXE boot a LiveCD image

Summary: I have wanted to build a kickstart environment which hosted a "rescue CD" or LiveCD to allow you to boot over the network after you blew your stuff up and needed to repair a few things.  Today I have worked through a method of doing so, with the help of the people who published a succinct script with the Red Hat Enterprise Virtualization Hypervisor.  (the script will be at the bottom of this post - if I have somehow not followed the GPL, please let me know and I will correct whatever is necessary) NOTE/Warning: The boot will fail due the initrd being too large (645mb).  I'm not sure how to proceed.  This procedure worked for RHEVh, because it is quite a bit smaller.  Hopefully I can report back with progress on this? :-$ Procedure: download your LiveCD image to /export/isos/RESCUE/Fedora-16-i686-Live-Desktop.iso # cd /var/tmp # vi livecd-iso-to-pxeboot (populate the file with the script shown below) # chmod 754 ./livecd-iso-to-pxeb...

"Error getting authority: Error initializing authority: Could not connect: No such file or directory (g-io-error-quark, 1)"

"Error getting authority: Error initializing authority: Could not connect: No such file or directory (g-io-error-quark, 1)" One issue that may cause this to arise is if you managed to break your /etc/fstab We had an engineer add a line with the intended options of "nfsvers=3" but instead added "-onfsvers=3" and it broke the system fairly catastrophically.

MOTD with colors! (also applies to shell profiles)

I'm not sure why I had never looked into this before, but this evening I became obsessed with discovering how to present different colored text in the /etc/motd. A person had suggested creating a shell script (rather than using special editing modes in vi, or something) and I agree that is the simplest way of getting this accomplished quickly. This most noteworthy portion of this script is the following: RESET="\033[0m" that puts the users shell back to the original color. I typically like a green text on black background. Also - a great reference for the different colors and font-type (underscore, etc...) https://wiki.archlinux.org/index.php/Color_Bash_Prompt I found this example on the web and I wish I could recall where so that I could provide credit to that person. #!/bin/bash #define the filename to use as output motd="/etc/motd" # Collect useful information about your system # $USER is automatically defined HOSTNAME=`uname -n` KERNEL=`un...