ืžื“ืจื™ืš ืœืžืชื—ื™ืœื™ื ืœ-SELinux

ืžื“ืจื™ืš ืœืžืชื—ื™ืœื™ื ืœ-SELinux

ืชืจื’ื•ื ื”ืžืืžืจ ืฉื”ื•ื›ืŸ ืœืชืœืžื™ื“ื™ ื”ืงื•ืจืก "ืื‘ื˜ื—ืช ืœื™ื ื•ืงืก"

SELinux ืื• Security Enhanced Linux ื”ื•ื ืžื ื’ื ื•ืŸ ื‘ืงืจืช ื’ื™ืฉื” ืžืฉื•ืคืจ ืฉืคื•ืชื— ืขืœ ื™ื“ื™ ื”ืกื•ื›ื ื•ืช ืœื‘ื™ื˜ื—ื•ืŸ ืœืื•ืžื™ ืฉืœ ืืจื”"ื‘ (NSA) ื›ื“ื™ ืœืžื ื•ืข ื—ื“ื™ืจื•ืช ื–ื“ื•ื ื™ื•ืช. ื”ื™ื ืžื™ื™ืฉืžืช ืžื•ื“ืœ ื‘ืงืจืช ื’ื™ืฉื” ืžืื•ืœืฆืช (ืื• ื—ื•ื‘ื”) (English Mandatory Access Control, MAC) ืขืœ ื’ื‘ื™ ื”ืžื•ื“ืœ ื”ืงื™ื™ื (ืื• ืกืœืงื˜ื™ื‘ื™) ื”ืงื™ื™ื (English Discretionary Access Control, DAC), ื›ืœื•ืžืจ, ื”ืจืฉืื•ืช ืงืจื™ืื”, ื›ืชื™ื‘ื”, ื‘ื™ืฆื•ืข.

ืœ-SELinux ื™ืฉ ืฉืœื•ืฉื” ืžืฆื‘ื™ื:

  1. ืื›ื™ืคื” - ืžื ื™ืขืช ื’ื™ืฉื” ื‘ื”ืชื‘ืกืก ืขืœ ื›ืœืœื™ ืžื“ื™ื ื™ื•ืช.
  2. ืžึทืชึดื™ืจ - ื ื™ื”ื•ืœ ื™ื•ืžืŸ ืฉืœ ืคืขื•ืœื•ืช ืฉืžืคืจื•ืช ืืช ื”ืžื“ื™ื ื™ื•ืช, ืืฉืจ ื™ื”ื™ื• ืืกื•ืจื•ืช ื‘ืžืฆื‘ ื”ืื›ื™ืคื”.
  3. ืœื ื›ื™ื - ื”ืฉื‘ืชื” ืžืœืื” ืฉืœ SELinux.

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”ื”ื’ื“ืจื•ืช ื ืžืฆืื•ืช /etc/selinux/config

ืฉื™ื ื•ื™ ืžืฆื‘ื™ SELinux

ื›ื“ื™ ืœื‘ืจืจ ืืช ื”ืžืฆื‘ ื”ื ื•ื›ื—ื™, ื”ืคืขืœ

$ getenforce

ื›ื“ื™ ืœืฉื ื•ืช ืืช ื”ืžืฆื‘ ืœืžืชื™ืจื ื™ ื”ืคืขืœ ืืช ื”ืคืงื•ื“ื” ื”ื‘ืื”

$ setenforce 0

ืื•, ื›ื“ื™ ืœืฉื ื•ืช ืืช ื”ืžืฆื‘ ืžืชื™ืจื ื™ ืขืœ ืื›ื™ืคื”, ืœื‘ืฆืข

$ setenforce 1

ืื ืืชื” ืฆืจื™ืš ืœื”ืฉื‘ื™ืช ืœื—ืœื•ื˜ื™ืŸ ืืช SELinux, ืื– ื–ื” ื™ื›ื•ืœ ืœื”ื™ืขืฉื•ืช ืจืง ื“ืจืš ืงื•ื‘ืฅ ื”ืชืฆื•ืจื”

$ vi /etc/selinux/config

ื›ื“ื™ ืœื”ืฉื‘ื™ืช, ืฉื ื” ืืช ื”ืคืจืžื˜ืจ SELINUX ื‘ืื•ืคืŸ ื”ื‘ื:

SELINUX=disabled

ื”ื’ื“ืจืช SELinux

ื›ืœ ืงื•ื‘ืฅ ื•ืชื”ืœื™ืš ืžืกื•ืžื ื™ื ื‘ื”ืงืฉืจ ืฉืœ SELinux, ื”ืžื›ื™ืœ ืžื™ื“ืข ื ื•ืกืฃ ื›ื’ื•ืŸ ืžืฉืชืžืฉ, ืชืคืงื™ื“, ืกื•ื’ ื•ื›ื•'. ืื ื–ื• ื”ืคืขื ื”ืจืืฉื•ื ื” ืฉืืชื” ืžืคืขื™ืœ ืืช SELinux, ืชื—ื™ืœื” ืชืฆื˜ืจืš ืœื”ื’ื“ื™ืจ ืืช ื”ื”ืงืฉืจ ื•ื”ืชื•ื•ื™ื•ืช. ืชื”ืœื™ืš ื”ืงืฆืืช ืชื•ื•ื™ื•ืช ื•ื”ืงืฉืจ ื™ื“ื•ืข ื›ืชื™ื•ื’. ื›ื“ื™ ืœื”ืชื—ื™ืœ ืœืกืžืŸ, ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ืื ื• ืžืฉื ื™ื ืืช ื”ืžืฆื‘ ืœ ืžืชื™ืจื ื™.

$ vi /etc/selinux/config
SELINUX=permissive

ืœืื—ืจ ื”ื’ื“ืจืช ื”ืžืฆื‘ ืžืชื™ืจื ื™, ืฆื•ืจ ืงื•ื‘ืฅ ื ืกืชืจ ืจื™ืง ื‘ืฉื•ืจืฉ ืขื ื”ืฉื autorelabel

$ touch /.autorelabel

ื•ื”ืคืขืœ ืžื—ื“ืฉ ืืช ื”ืžื—ืฉื‘

$ init 6

ื”ืขืจื”: ืื ื• ืžืฉืชืžืฉื™ื ื‘ืžืฆื‘ ืžืชื™ืจื ื™ ืœืกื™ืžื•ืŸ, ืžืื– ื”ืฉื™ืžื•ืฉ ื‘ืžืฆื‘ ืื›ื™ืคื” ืขืœื•ืœ ืœื’ืจื•ื ืœืžืขืจื›ืช ืœืงืจื•ืก ื‘ืžื”ืœืš ืืชื—ื•ืœ ืžื—ื“ืฉ.

ืืœ ืชื“ืื’ ืื ื”ื”ื•ืจื“ื” ื ืชืงืขืช ื‘ืงื•ื‘ืฅ ื›ืœืฉื”ื•, โ€‹โ€‹ื”ืกื™ืžื•ืŸ ืœื•ืงื— ื–ืžืŸ ืžื”. ืœืื—ืจ ื”ืฉืœืžืช ื”ืกื™ืžื•ืŸ ื•ื”ืžืขืจื›ืช ืฉืœืš ืžื•ืคืขืœืช, ืืชื” ื™ื›ื•ืœ ืœืœื›ืช ืœืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ื•ืœื”ื’ื“ื™ืจ ืืช ื”ืžืฆื‘ ืื›ื™ืคื”ื•ื’ื ืœื”ืจื™ืฅ:

$ setenforce 1

ื”ืคืขืœืช ื‘ื”ืฆืœื—ื” ืืช SELinux ื‘ืžื—ืฉื‘ ืฉืœืš.

ื ื™ื˜ื•ืจ ื”ื™ื•ืžื ื™ื

ื™ื™ืชื›ืŸ ืฉื ืชืงืœืช ื‘ืฉื’ื™ืื•ืช ืžืกื•ื™ืžื•ืช ื‘ืžื”ืœืš ื”ืกื™ืžื•ืŸ ืื• ื‘ื–ืžืŸ ืฉื”ืžืขืจื›ืช ืคื•ืขืœืช. ื›ื“ื™ ืœื‘ื“ื•ืง ืื ื”-SELinux ืฉืœืš ืคื•ืขืœ ื›ื”ืœื›ื” ื•ืื ื”ื•ื ืœื ื—ื•ืกื ื’ื™ืฉื” ืœืฉื•ื ื™ืฆื™ืื”, ืืคืœื™ืงืฆื™ื” ื•ื›ื•', ืขืœื™ืš ืœื”ืกืชื›ืœ ื‘ื™ื•ืžื ื™ื. ื™ื•ืžืŸ ื”-SELinux ื ืžืฆื ื‘ /var/log/audit/audit.log, ืื‘ืœ ืืชื” ืœื ืฆืจื™ืš ืœืงืจื•ื ืืช ื›ื•ืœื• ื›ื“ื™ ืœืžืฆื•ื ืฉื’ื™ืื•ืช. ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช audit2why ื›ื“ื™ ืœืžืฆื•ื ืฉื’ื™ืื•ืช. ื”ืคืขืœ ืืช ื”ืคืงื•ื“ื” ื”ื‘ืื”:

$ audit2why < /var/log/audit/audit.log

ื›ืชื•ืฆืื” ืžื›ืš, ืชืงื‘ืœ ืจืฉื™ืžื” ืฉืœ ืฉื’ื™ืื•ืช. ืื ืœื ื”ื™ื• ืฉื’ื™ืื•ืช ื‘ื™ื•ืžืŸ, ืœื ื™ื•ืฆื’ื• ื”ื•ื“ืขื•ืช.

ื”ื’ื“ืจืช ืžื“ื™ื ื™ื•ืช SELinux

ืžื“ื™ื ื™ื•ืช SELinux ื”ื™ื ืžืขืจื›ืช ื›ืœืœื™ื ื”ืฉื•ืœื˜ืช ื‘ืžื ื’ื ื•ืŸ ื”ืื‘ื˜ื—ื” ืฉืœ SELinux. ืžื“ื™ื ื™ื•ืช ืžื’ื“ื™ืจื” ืžืขืจื›ืช ื›ืœืœื™ื ืขื‘ื•ืจ ืกื‘ื™ื‘ื” ืกืคืฆื™ืคื™ืช. ื›ืขืช ื ืœืžื“ ื›ื™ืฆื“ ืœื”ื’ื“ื™ืจ ืžื“ื™ื ื™ื•ืช ื›ื“ื™ ืœืืคืฉืจ ื’ื™ืฉื” ืœืฉื™ืจื•ืชื™ื ืืกื•ืจื™ื.

1. ืขืจื›ื™ื ืœื•ื’ื™ื™ื (ืžืชื’ื™ื)

ืžืชื’ื™ื (ื‘ื•ืœื™ืื ื™ื) ืžืืคืฉืจื™ื ืœืš ืœืฉื ื•ืช ื—ืœืงื™ื ืฉืœ ืžื“ื™ื ื™ื•ืช ื‘ื–ืžืŸ ืจื™ืฆื”, ืžื‘ืœื™ ืœื™ืฆื•ืจ ืžื“ื™ื ื™ื•ืช ื—ื“ืฉื”. ื”ื ืžืืคืฉืจื™ื ืœืš ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ืžื‘ืœื™ ืœื‘ืฆืข ืืชื—ื•ืœ ืžื—ื“ืฉ ืื• ื”ื™ื“ื•ืจ ืžื—ื“ืฉ ืฉืœ ืžื“ื™ื ื™ื•ืช SELinux.

ื“ื•ื’ืžื”
ื ื ื™ื— ืฉืื ื—ื ื• ืจื•ืฆื™ื ืœืฉืชืฃ ืืช ืกืคืจื™ื™ืช ื”ื‘ื™ืช ืฉืœ ืžืฉืชืžืฉ ื“ืจืš ืงืจื™ืื”/ื›ืชื™ื‘ื” FTP, ื•ื›ื‘ืจ ืฉื™ืชืคื ื• ืื•ืชื”, ืื‘ืœ ื›ืฉืื ื—ื ื• ืžื ืกื™ื ืœื’ืฉืช ืืœื™ื”, ืื ื—ื ื• ืœื ืจื•ืื™ื ื›ืœื•ื. ื”ืกื™ื‘ื” ืœื›ืš ื”ื™ื ืฉืžื“ื™ื ื™ื•ืช SELinux ืžื•ื ืขืช ืžืฉืจืช ื”-FTP ืœืงืจื•ื ื•ืœื›ืชื•ื‘ ืœืกืคืจื™ื™ืช ื”ื‘ื™ืช ืฉืœ ื”ืžืฉืชืžืฉ. ืขืœื™ื ื• ืœืฉื ื•ืช ืืช ื”ืžื“ื™ื ื™ื•ืช ื›ืš ืฉืฉืจืช ื”-FTP ื™ื•ื›ืœ ืœื’ืฉืช ืœืกืคืจื™ื•ืช ื”ื‘ื™ืชื™ื•ืช. ื‘ื•ื ื ืจืื” ืื โ€‹โ€‹ื™ืฉ ืžืชื’ื™ื ืœื–ื” ืขืœ ื™ื“ื™ ื‘ื™ืฆื•ืข

$ semanage boolean -l

ืคืงื•ื“ื” ื–ื• ืชืคืจื˜ ืืช ื”ืžืชื’ื™ื ื”ื–ืžื™ื ื™ื ืขื ืžืฆื‘ื ื”ื ื•ื›ื—ื™ (ืžื•ืคืขืœ ืื• ื›ื‘ื•ื™) ื•ืชื™ืื•ืจ. ืืชื” ื™ื›ื•ืœ ืœืฆืžืฆื ืืช ื”ื—ื™ืคื•ืฉ ืฉืœืš ืขืœ ื™ื“ื™ ื”ื•ืกืคืช grep ื›ื“ื™ ืœืžืฆื•ื ืชื•ืฆืื•ืช ftp ื‘ืœื‘ื“:

$ semanage boolean -l | grep ftp

ื•ืชืžืฆื ืืช ื”ื“ื‘ืจื™ื ื”ื‘ืื™ื

ftp_home_dir        -> off       Allow ftp to read & write file in user home directory

ืžืชื’ ื–ื” ืžื•ืฉื‘ืช, ืื– ื ืคืขื™ืœ ืื•ืชื• ืขื setsebool $ setsebool ftp_home_dir on

ื›ืขืช ื“ืžื•ืŸ ื”-ftp ืฉืœื ื• ื™ื•ื›ืœ ืœื’ืฉืช ืœืกืคืจื™ื™ืช ื”ื‘ื™ืช ืฉืœ ื”ืžืฉืชืžืฉ.
ื”ืขืจื”: ืืชื” ื™ื›ื•ืœ ื’ื ืœืงื‘ืœ ืจืฉื™ืžื” ืฉืœ ืžืชื’ื™ื ื–ืžื™ื ื™ื ืœืœื ืชื™ืื•ืจ ืขืœ ื™ื“ื™ ื‘ื™ืฆื•ืข getsebool -a

2. ืชื•ื•ื™ื•ืช ื•ื”ืงืฉืจ

ื–ื•ื”ื™ ื”ื“ืจืš ื”ื ืคื•ืฆื” ื‘ื™ื•ืชืจ ืœื™ื™ืฉื ืืช ืžื“ื™ื ื™ื•ืช SELinux. ื›ืœ ืงื•ื‘ืฅ, ืชื™ืงื™ื”, ืชื”ืœื™ืš ื•ื™ืฆื™ืื” ืžืกื•ืžื ื™ื ื‘ื”ืงืฉืจ ืฉืœ SELinux:

  • ืขื‘ื•ืจ ืงื‘ืฆื™ื ื•ืชื™ืงื™ื•ืช, ื”ืชื•ื•ื™ื•ืช ืžืื•ื—ืกื ื•ืช ื›ืชื›ื•ื ื•ืช ืžื•ืจื—ื‘ื•ืช ื‘ืžืขืจื›ืช ื”ืงื‘ืฆื™ื ื•ื ื™ืชืŸ ืœืฆืคื•ืช ื‘ื”ืŸ ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” ื”ื‘ืื”:
    $ ls -Z /etc/httpd
  • ืขื‘ื•ืจ ืชื”ืœื™ื›ื™ื ื•ื™ืฆื™ืื•ืช, ื”ืชื•ื•ื™ืช ืžื ื•ื”ืœืช ืขืœ ื™ื“ื™ ื”ืœื™ื‘ื”, ื•ืชื•ื›ืœ ืœื”ืฆื™ื’ ืืช ื”ืชื•ื•ื™ื•ืช ื”ืืœื” ื‘ืื•ืคืŸ ื”ื‘ื:

ืชื”ืœื™ืš

$ ps โ€“auxZ | grep httpd

ื”ื ืžืœ

$ netstat -anpZ | grep httpd

ื“ื•ื’ืžื”
ื›ืขืช ื ืกืชื›ืœ ืขืœ ื“ื•ื’ืžื” ื›ื“ื™ ืœื”ื‘ื™ืŸ ื˜ื•ื‘ ื™ื•ืชืจ ืืช ื”ืชื•ื•ื™ื•ืช ื•ื”ื”ืงืฉืจ. ื ื ื™ื— ืฉื™ืฉ ืœื ื• ืฉืจืช ืื™ื ื˜ืจื ื˜, ื‘ืžืงื•ื ืกืคืจื™ื™ื” /var/www/html/ ะธัะฟะพะปัŒะทัƒะตั‚ /home/dan/html/. SELinux ืชืจืื” ื‘ื›ืš ื”ืคืจื” ืฉืœ ืžื“ื™ื ื™ื•ืช ื•ืœื ืชื•ื›ืœ ืœืฆืคื•ืช ื‘ื“ืคื™ ื”ืื™ื ื˜ืจื ื˜ ืฉืœืš. ื”ืกื™ื‘ื” ืœื›ืš ื”ื™ื ืฉืœื ืงื‘ืขื ื• ืืช ื”ืงืฉืจ ื”ืื‘ื˜ื—ื” ื”ืžืฉื•ื™ืš ืœืงื•ื‘ืฆื™ HTML. ื›ื“ื™ ืœื”ืฆื™ื’ ืืช ื”ืงืฉืจ ื”ืื‘ื˜ื—ื” ื”ืžื•ื’ื“ืจ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” ื”ื‘ืื”:

$ ls โ€“lz /var/www/html
 -rw-rโ€”rโ€”. root root unconfined_u:object_r:httpd_sys_content_t:s0 /var/www/html/

ื”ื ื” ื”ื’ืขื ื• httpd_sys_content_t ื›ื”ืงืฉืจ ืขื‘ื•ืจ ืงื‘ืฆื™ HTML. ืขืœื™ื ื• ืœื”ื’ื“ื™ืจ ืืช ื”ืงืฉืจ ื”ืื‘ื˜ื—ื” ื”ื–ื” ืขื‘ื•ืจ ื”ืกืคืจื™ื™ื” ื”ื ื•ื›ื—ื™ืช ืฉืœื ื•, ืฉื›ืจื’ืข ื™ืฉ ืœื” ืืช ื”ื”ืงืฉืจ ื”ื‘ื:

-rw-rโ€”rโ€”. dan dan system_u:object_r:user_home_t:s0 /home/dan/html/

ืคืงื•ื“ื” ื—ืœื•ืคื™ืช ืœื‘ื“ื™ืงืช ื”ืงืฉืจ ื”ืื‘ื˜ื—ื” ืฉืœ ืงื•ื‘ืฅ ืื• ืกืคืจื™ื”:

$ semanage fcontext -l | grep '/var/www'

ื ืฉืชืžืฉ ื’ื ื‘-semanage ื›ื“ื™ ืœืฉื ื•ืช ืืช ื”ื”ืงืฉืจ ืœืื—ืจ ืฉืžืฆืื ื• ืืช ื”ืงืฉืจ ื”ืื‘ื˜ื—ื” ื”ื ื›ื•ืŸ. ื›ื“ื™ ืœืฉื ื•ืช ืืช ื”ื”ืงืฉืจ ืฉืœ /home/dan/html, ื”ืคืขืœ ืืช ื”ืคืงื•ื“ื•ืช ื”ื‘ืื•ืช:

$ semanage fcontext -a -t httpd_sys_content_t โ€˜/home/dan/html(/.*)?โ€™
$ semanage fcontext -l | grep โ€˜/home/dan/htmlโ€™
/home/dan/html(/.*)? all files system_u:object_r:httpd_sys_content_t:s0
$ restorecon -Rv /home/dan/html

ืœืื—ืจ ืฉื™ื ื•ื™ ื”ื”ืงืฉืจ ื‘ืืžืฆืขื•ืช Semanage, ื”ืคืงื•ื“ื” restorecon ืชื˜ืขืŸ ืืช ื”ืงืฉืจ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืขื‘ื•ืจ ืงื‘ืฆื™ื ื•ืกืคืจื™ื•ืช. ืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ืฉืœื ื• ื™ื•ื›ืœ ื›ืขืช ืœืงืจื•ื ืงื‘ืฆื™ื ืžื”ืชื™ืงื™ื™ื” /home/dan/htmlืžื›ื™ื•ื•ืŸ ืฉื”ืงืฉืจ ื”ืื‘ื˜ื—ื” ืขื‘ื•ืจ ืชื™ืงื™ื” ื–ื• ื”ืฉืชื ื” ืœ httpd_sys_content_t.

3. ืฆื•ืจ ืžื“ื™ื ื™ื•ืช ืžืงื•ืžื™ืช

ื™ื™ืชื›ื ื• ืžืฆื‘ื™ื ืฉื‘ื”ื ื”ืฉื™ื˜ื•ืช ื”ื "ืœ ืœื ืžื•ืขื™ืœื•ืช ืœืš ื•ืืชื” ืžืงื‘ืœ ืฉื’ื™ืื•ืช (avc/denial) ื‘-audit.log. ื›ืืฉืจ ื–ื” ืงื•ืจื”, ืขืœื™ืš ืœื™ืฆื•ืจ ืžื“ื™ื ื™ื•ืช ืžืงื•ืžื™ืช. ืืชื” ื™ื›ื•ืœ ืœืžืฆื•ื ืืช ื›ืœ ื”ืฉื’ื™ืื•ืช ื‘ืืžืฆืขื•ืช audit2why, ื›ืžืชื•ืืจ ืœืขื™ืœ.

ืืชื” ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืžื“ื™ื ื™ื•ืช ืžืงื•ืžื™ืช ื›ื“ื™ ืœืคืชื•ืจ ืฉื’ื™ืื•ืช. ืœื“ื•ื’ืžื”, ืื ื• ืžืงื‘ืœื™ื ืฉื’ื™ืื” ื”ืงืฉื•ืจื” ืœ-httpd (apache) ืื• smbd (samba), ืื ื• ืžื‘ืฆืขื™ื grep ืฉืœ ื”ืฉื’ื™ืื•ืช ื•ื™ื•ืฆืจื™ื ืขื‘ื•ืจืŸ ืžื“ื™ื ื™ื•ืช:

apache
$ grep httpd_t /var/log/audit/audit.log | audit2allow -M http_policy
samba
$ grep smbd_t /var/log/audit/audit.log | audit2allow -M smb_policy

ื›ืืŸ http_policy ะธ smb_policy ื”ื ืฉืžื•ืช ื”ืžื“ื™ื ื™ื•ืช ื”ืžืงื•ืžื™ืช ืฉื™ืฆืจื ื•. ื›ืขืช ืขืœื™ื ื• ืœื˜ืขื•ืŸ ืืช ื”ืžื“ื™ื ื™ื•ืช ื”ืžืงื•ืžื™ืช ืฉื ื•ืฆืจื” ืœืžื“ื™ื ื™ื•ืช ื”-SELinux ื”ื ื•ื›ื—ื™ืช. ื ื™ืชืŸ ืœืขืฉื•ืช ื–ืืช ื‘ืื•ืคืŸ ื”ื‘ื:

$ semodule โ€“I http_policy.pp
$ semodule โ€“I smb_policy.pp

ื”ืžื“ื™ื ื™ื•ืช ื”ืžืงื•ืžื™ืช ืฉืœื ื• ื”ื•ืจื“ื” ื•ืื ื• ืœื ืืžื•ืจื™ื ืœืงื‘ืœ ืขื•ื“ AVC ืื• ื“ื ื™ื™ืœ ื‘-audit.log.

ื–ื” ื”ื™ื” ื”ื ื™ืกื™ื•ืŸ ืฉืœื™ ืœืขื–ื•ืจ ืœืš ืœื”ื‘ื™ืŸ ืืช SELinux. ืื ื™ ืžืงื•ื•ื” ืฉืื—ืจื™ ืงืจื™ืืช ืžืืžืจ ื–ื” ืชืจื’ื™ืฉื• ื™ื•ืชืจ ื‘ื ื•ื— ืขื SELinux.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”