Selinux

From TheBeard Science Project Wiki
Revision as of 17:37, 29 February 2016 by Beard (talk | contribs) (Created page with "<pre> packages: policycoreutils-gui - selinux gui tool system-config-selinux system-config-firewall configs: /selinux /etc/selinux/config /etc/selinux/targeted - targe...")

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search
packages:
	policycoreutils-gui - selinux gui tool
	system-config-selinux
	system-config-firewall
	
configs:
	/selinux
	/etc/selinux/config
	/etc/selinux/targeted - targeted rules

commands:
	getenforce - show current mode
	getsebool -a - show boolean list (grep it)
	sestatus -v - show general selinux info
	setenforce <mode> - set mode (enforcing, permissive, disabled)
	setsebool <boolean_value> <on/off> - change boolean value
		-P - set permanent/boot. default is only temporary

config args:
	SELINUX = <enforcing|permissive|disabled>
	SELINUXTYPE = <targeted|strict>
		targeted - only targeted network daemons
		strict - all daemons