{"id":36280,"date":"2019-10-31T22:10:39","date_gmt":"2019-10-31T19:10:39","guid":{"rendered":"https:\/\/prohoster.info\/blog\/rukovodstvo-dlya-nachinayushhih-po-selinux\/"},"modified":"2019-10-31T22:10:39","modified_gmt":"2019-10-31T19:10:39","slug":"rukovodstvo-dlya-nachinayushhih-po-selinux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/rukovodstvo-dlya-nachinayushhih-po-selinux","title":{"rendered":"Udh\u00ebzuesi p\u00ebr t\u00eb fillestar\u00ebt p\u00ebr SELinux","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Udh\u00ebzuesi p\u00ebr t\u00eb fillestar\u00ebt p\u00ebr SELinux\" src=\"\/wp-content\/uploads\/2019\/07\/4e1443c8b79a8dfa1b28fb6b6d0666bb.png\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p><em>P\u00ebrkthimi i artikullit \u00ebsht\u00eb p\u00ebrgatitur p\u00ebr student\u00ebt e kursit <noindex><a rel=\"nofollow\" href=\"https:\/\/otus.pw\/31Eb\/\">\u00abSiguria e Linux\u00bb<\/a><\/noindex><\/em><\/p>\n<p>SELinux ose Security Enhanced Linux \u00ebsht\u00eb nj\u00eb mekaniz\u00ebm i avancuar i kontrollit t\u00eb aksesit, i zhvilluar nga Agjencia e Siguris\u00eb Komb\u00ebtare t\u00eb SHBA (NSA) p\u00ebr t\u00eb parandaluar dep\u00ebrtimet e keqdashura. Ai zbatohet nj\u00eb model t\u00eb detyruar (ose mandatar) t\u00eb kontrollit t\u00eb aksesit (angl. Mandatory Access Control, MAC) mbi modelin ekzistues diskrecional (ose selektiv) t\u00eb kontrollit t\u00eb aksesit (angl. Discretionary Access Control, DAC), q\u00eb do t\u00eb thot\u00eb lejet p\u00ebr lexim, shkruajtes\u00eb dhe ekzekutim.<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p><\/p>\n<p>SELinux ka tre mund\u00ebsi operimi:<\/p>\n<p><\/p>\n<ol>\n<li><strong>Enforcing<\/strong> \u2014 ndalon aksesin mbi baz\u00ebn e rregullave t\u00eb politik\u00ebs.<\/li>\n<li><strong>Permissive<\/strong> \u2014 regjistron veprimet q\u00eb shkelin politik\u00ebn, t\u00eb cilat n\u00eb m\u00ebnyr\u00ebn enforcing do ishin ndaluar.<\/li>\n<li><strong>\u00c7aktivizuar<\/strong> \u2014 \u00e7aktivizimi i plot\u00eb i SELinux.<\/li>\n<\/ol>\n<p><\/p>\n<p>P\u00ebr default, cil\u00ebsimet ndodhen n\u00eb <code>\/etc\/selinux\/config<\/code><\/p>\n<p><\/p>\n<h1 id=\"izmenenie-rezhimov-selinux\">Modifikimi i mund\u00ebsive t\u00eb operimit t\u00eb SELinux<\/h1>\n<p><\/p>\n<p>P\u00ebr t\u00eb par\u00eb mund\u00ebsin\u00eb aktuale, ekzekutoni <\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ getenforce<\/code><\/pre>\n<p><\/p>\n<p>P\u00ebr t\u00eb ndryshuar mund\u00ebsin\u00eb n\u00eb permissive, ekzekutoni komand\u00ebn n\u00eb vijim <\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ setenforce 0<\/code><\/pre>\n<p><\/p>\n<p>ose, p\u00ebr t\u00eb ndryshuar mund\u00ebsin\u00eb nga <strong>permissive<\/strong> n\u00eb <strong>enforcing<\/strong>, ekzekutoni <\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ setenforce 1<\/code><\/pre>\n<p><\/p>\n<p>N\u00ebse ju nevojitet t\u00eb \u00e7aktivizoni plot\u00ebsisht SELinux, at\u00ebher\u00eb mund ta b\u00ebni k\u00ebt\u00eb vet\u00ebm p\u00ebrmes sked\u00ebs s\u00eb konfigurimit <\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ vi \/etc\/selinux\/config<\/code><\/pre>\n<p><\/p>\n<p>P\u00ebr ta \u00e7aktivizuar, ndryshoni parametrin SELINUX n\u00eb k\u00ebt\u00eb m\u00ebnyr\u00eb:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">SELINUX=disabled<\/code><\/pre>\n<p><\/p>\n<h1 id=\"nastroyka-selinux\">Cil\u00ebsimi i SELinux<\/h1>\n<p><\/p>\n<p>\u00c7do sked\u00eb dhe proces sh\u00ebnohet me kontekstin SELinux, i cili p\u00ebrmban informacion shtes\u00eb si p\u00ebrdoruesi, roli, tipi, etj. N\u00ebse e aktivizoni p\u00ebr her\u00eb t\u00eb par\u00eb SELinux, duhet fillimisht t\u00eb konfiguroni kontekstin dhe etiketat. Procesi i vendosjes s\u00eb etiketave dhe konteksteve njihet si etiketimi. P\u00ebr t\u00eb filluar etiketimin, n\u00eb sked\u00ebn e konfigurimit ndryshoni mund\u00ebsin\u00eb n\u00eb <strong>permissive<\/strong>.<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ vi \/etc\/selinux\/config\nSELINUX=permissive<\/code><\/pre>\n<p><\/p>\n<p>Pasi t\u00eb keni vendosur mund\u00ebsin\u00eb <strong>permissive<\/strong>, krijoni nj\u00eb sked\u00eb t\u00eb fsheht\u00eb t\u00eb zbraz\u00ebt me emrin <code>.autorelabel<\/code><\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ touch \/.autorelabel<\/code><\/pre>\n<p><\/p>\n<p>dhe ri-ngarkoni kompjuterin<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ init 6<\/code><\/pre>\n<p><\/p>\n<p>Sh\u00ebnim: ne p\u00ebrdorim mund\u00ebsin\u00eb <strong>permissive<\/strong> p\u00ebr etiketim, pasi p\u00ebrdorimi i mund\u00ebsis\u00eb <strong>enforcing<\/strong> mund t\u00eb \u00e7oj\u00eb n\u00eb r\u00ebnien e sistemit gjat\u00eb ri-ngarkimit.<\/p>\n<p><\/p>\n<p>Mos u shqet\u00ebsoni, n\u00ebse ngarkimi ngec n\u00eb ndonj\u00eb sked\u00eb, etiketimi merr disa koh\u00eb. Pasi t\u00eb p\u00ebrfundoj\u00eb etiketimi dhe ngarkimi i sistemit tuaj, mund t\u00eb shkoni te skeda e konfigurimit dhe t\u00eb vendosni mund\u00ebsin\u00eb <strong>enforcing<\/strong>, si dhe t\u00eb ekzekutoni:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ setenforce 1<\/code><\/pre>\n<p><\/p>\n<p>Tani keni aktivizuar me sukses SELinux n\u00eb kompjuterin tuaj. <\/p>\n<p><\/p>\n<h1 id=\"monitorim-logi\">Monitorimi i log\u00ebve<\/h1>\n<p><\/p>\n<p>Mund t\u00eb keni pasur ndonj\u00eb problem gjat\u00eb etiketimit ose gjat\u00eb funksionimit t\u00eb sistemit. P\u00ebr t\u00eb kontrolluar n\u00ebse SELinux juaj funksionon si\u00e7 duhet dhe nuk po bllokon qasje n\u00eb ndonj\u00eb port, aplikacion etj., nevojitet t\u00eb shikoni log\u00ebt. Logu i SELinux ndodhet n\u00eb <code>\/var\/log\/audit\/audit.log<\/code>, por ju nuk keni nevoj\u00eb ta lexoni t\u00ebr\u00ebsisht p\u00ebr t\u00eb gjetur gabimet. Mund t\u00eb p\u00ebrdorni mjetin audit2why p\u00ebr t\u00eb gjetur gabimet. Ekzekutoni komand\u00ebn e m\u00ebposhtme:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ audit2why &lt; \/var\/log\/audit\/audit.log<\/code><\/pre>\n<p><\/p>\n<p>Si rezultat, do t\u00eb merrni nj\u00eb list\u00eb gabimesh. N\u00ebse nuk ka gabimesh n\u00eb log, asnj\u00eb mesazh nuk do t\u00eb shfaqet.<\/p>\n<p><\/p>\n<h1 id=\"nastroyka-politiki-selinux\">Konfigurimi i politik\u00ebs SELinux<\/h1>\n<p><\/p>\n<p>Politika SELinux \u00ebsht\u00eb nj\u00eb grumbull rregullash q\u00eb ndjek mekanizmi i siguris\u00eb SELinux. Politika p\u00ebrcakton nj\u00eb set rregullash p\u00ebr nj\u00eb ambient t\u00eb caktuar. Tani do t\u00eb shqyrtojm\u00eb si t\u00eb konfigurojm\u00eb politikat p\u00ebr t\u00eb lejuar qasje n\u00eb sh\u00ebrbime t\u00eb ndaluara.<\/p>\n<p><\/p>\n<h4 id=\"1-logicheskie-znacheniya-pereklyuchateli\">1. Vlera logjike (\u00e7elsa)<\/h4>\n<p><\/p>\n<p>\u00c7el\u00ebsat (booleans) lejojn\u00eb t\u00eb ndryshoni pjes\u00eb t\u00eb politik\u00ebs gjat\u00eb pun\u00ebs, pa nevoj\u00ebn p\u00ebr t\u00eb krijuar politika t\u00eb reja. Ato lejojn\u00eb t\u00eb b\u00ebni ndryshime pa rindizjen ose rikompilimin e politikave SELinux.<\/p>\n<p><\/p>\n<p><strong>Shembulli<\/strong><br \/>\nSupozoni se duam t\u00eb ofrojm\u00eb qasje n\u00eb katalogun e sht\u00ebpis\u00eb s\u00eb p\u00ebrdoruesit p\u00ebr FTP n\u00eb lexim dhe shk write, dhe ne tashm\u00eb e kemi ndar\u00eb at\u00eb, por kur mundohemi t\u00eb qasje, nuk shohim asgj\u00eb. Kjo ndodh sepse politika SELinux i ndalon serverit FTP t\u00eb lexoj\u00eb dhe t\u00eb shkruaj\u00eb n\u00eb katalogun e sht\u00ebpis\u00eb s\u00eb p\u00ebrdoruesit. Na nevojitet t\u00eb ndryshojm\u00eb politik\u00ebn q\u00eb serveri FTP t\u00eb mund t\u00eb qaset n\u00eb katalog\u00ebt e sht\u00ebpis\u00eb. Le t\u00eb shohim n\u00ebse ka ndonj\u00eb \u00e7el\u00ebs p\u00ebr k\u00ebt\u00eb duke ekzekutuar<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ semanage boolean -l<\/code><\/pre>\n<p><\/p>\n<p>Kjo komand\u00eb do t\u00eb jap\u00eb nj\u00eb list\u00eb \u00e7el\u00ebsash t\u00eb disponuesh\u00ebm me gjendjen e tyre aktuale (e aktivizuar\/on ose e \u00e7aktivizuar\/off) dhe p\u00ebrshkrimin. Mund t\u00eb p\u00ebrcaktoni k\u00ebrkimin tuaj duke shtuar grep p\u00ebr t\u00eb gjetur rezultate q\u00eb i p\u00ebrkasin vet\u00ebm ftp:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ semanage boolean -l | grep ftp<\/code><\/pre>\n<p><\/p>\n<p>dhe do t\u00eb gjeni k\u00ebt\u00eb<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">ftp_home_dir -&gt; off       Lejo ftp t\u00eb lexoj\u00eb &amp; shkruaj\u00eb skedarin n\u00eb katalogun e sht\u00ebpis\u00eb s\u00eb p\u00ebrdoruesit<\/code><\/pre>\n<p><\/p>\n<p>Ky \u00e7el\u00ebs \u00ebsht\u00eb i \u00e7aktivizuar, k\u00ebshtu q\u00eb do ta aktivizojm\u00eb at\u00eb duke p\u00ebrdorur <code>setsebool $ setsebool ftp_home_dir on<\/code><\/p>\n<p><\/p>\n<p>Tani demonin ton\u00eb ftp do t\u00eb jet\u00eb n\u00eb gjendje t\u00eb qaset n\u00eb katalogun e sht\u00ebpis\u00eb s\u00eb p\u00ebrdoruesit.<br \/>\nSh\u00ebnim: mund t\u00eb merrni gjithashtu nj\u00eb list\u00eb t\u00eb \u00e7el\u00ebsave t\u00eb disponuesh\u00ebm pa p\u00ebrshkrim duke ekzekutuar <code>getsebool -a<\/code><\/p>\n<p><\/p>\n<h4 id=\"2-metki-i-kontekst\">2. Etiketat dhe konteksti<\/h4>\n<p><\/p>\n<p>Ky \u00ebsht\u00eb m\u00ebnyra m\u00eb e zakonshme p\u00ebr t\u00eb p\u00ebrmbushur politikat SELinux. \u00c7do skedar, dosje, proces dhe port etiketohen me kontekstin SELinux:<\/p>\n<p><\/p>\n<ul>\n<li>P\u00ebr skedar\u00ebt dhe dosjet, etiketat ruhen si atribute t\u00eb zgjeruara n\u00eb sistemin e skedar\u00ebve dhe mund t\u00eb shihen me komand\u00ebn e m\u00ebposhtme:\n<pre><code class=\"plaintext\">$ ls -Z \/etc\/httpd<\/code><\/pre>\n<\/li>\n<li>P\u00ebr proceset dhe portet, etiketimi menaxhohet nga b\u00ebrthama e sistemit, dhe mund t\u00eb shihni k\u00ebto etiketa n\u00eb k\u00ebt\u00eb m\u00ebnyr\u00eb:<\/li>\n<\/ul>\n<p><\/p>\n<p>nj\u00eb proces<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ ps \u2013auxZ | grep httpd<\/code><\/pre>\n<p><\/p>\n<p>port<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ netstat -anpZ | grep httpd<\/code><\/pre>\n<p><\/p>\n<p><strong>Shembulli<\/strong><br \/>\nTani, le t\u00eb shqyrtojm\u00eb nj\u00eb shembull p\u00ebr t\u00eb kuptuar m\u00eb mir\u00eb etiketat dhe kontekstin. Supozoni se kemi <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/\"   title=\"serverin web\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1142\">serverin web<\/a>, i cili n\u00eb vend t\u00eb dosjes <code>\/var\/www\/html\/ \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \/home\/dan\/html\/<\/code>. SELinux do ta konsideroj\u00eb k\u00ebt\u00eb nj\u00eb shkelje t\u00eb politik\u00ebs dhe nuk do t\u00eb keni mund\u00ebsi t\u00eb shihni faqet tuaja t\u00eb internetit. Kjo \u00ebsht\u00eb sepse ne nuk kemi vendosur kontekstin e siguris\u00eb t\u00eb lidhur me skedar\u00ebt HTML. P\u00ebr t\u00eb par\u00eb kontekstin e siguris\u00eb q\u00eb \u00ebsht\u00eb n\u00eb parazgjedhje, p\u00ebrdorni komand\u00ebn e m\u00ebposhtme:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ ls \u2013lz \/var\/www\/html\n -rw-r\u2014r\u2014. root root unconfined_u:object_r:httpd_sys_content_t:s0 \/var\/www\/html\/<\/code><\/pre>\n<p><\/p>\n<p>K\u00ebtu mor\u00ebm <code>httpd_sys_content_t<\/code> si kontekst p\u00ebr skedar\u00ebt html. Na nevojitet t\u00eb vendosim k\u00ebt\u00eb kontekst sigurie p\u00ebr dosjen ton\u00eb aktuale, e cila tani ka k\u00ebt\u00eb kontekst:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">-rw-r\u2014r\u2014. dan dan system_u:object_r:user_home_t:s0 \/home\/dan\/html\/<\/code><\/pre>\n<p><\/p>\n<p>Nj\u00eb komand\u00eb alternative p\u00ebr t\u00eb kontrolluar kontekstin e siguris\u00eb s\u00eb nj\u00eb skedari ose dosjeje:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ semanage fcontext -l | grep '\/var\/www'<\/code><\/pre>\n<p><\/p>\n<p>Ne gjithashtu do t\u00eb p\u00ebrdorim semanage p\u00ebr t\u00eb ndryshuar kontekstin, pasi t\u00eb gjejm\u00eb kontekstin e siguris\u00eb t\u00eb duhur. P\u00ebr t\u00eb ndryshuar kontekstin e \/home\/dan\/html, ekzekutoni komandat e m\u00ebposhtme:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ semanage fcontext -a -t httpd_sys_content_t '\/home\/dan\/html(\/.*)?'\n$ semanage fcontext -l | grep '\/home\/dan\/html'\n\/home\/dan\/html(\/.*)? all files system_u:object_r:httpd_sys_content_t:s0\n$ restorecon -Rv \/home\/dan\/html<\/code><\/pre>\n<p><\/p>\n<p>Pas ndryshimit t\u00eb kontekstit me semanage, komanda restorecon do t\u00eb ngarkoj\u00eb kontekstin n\u00eb parazgjedhje p\u00ebr skedar\u00ebt dhe dosjet. Serveri yn\u00eb i internetit tani do t\u00eb jet\u00eb n\u00eb gjendje t\u00eb lexoj\u00eb skedar\u00ebt nga dosja <code>\/home\/dan\/html<\/code>, p\u00ebr shkak se konteksti i siguris\u00eb p\u00ebr k\u00ebt\u00eb dosje u ndryshua n\u00eb <code>httpd_sys_content_t<\/code>.<\/p>\n<p><\/p>\n<h4 id=\"3-sozdanie-lokalnyh-politik\">3. Krijimi i politikave lokale<\/h4>\n<p><\/p>\n<p>Mund t\u00eb ndodhin situata ku metodat e m\u00ebparshme jan\u00eb t\u00eb pap\u00ebrdorshme p\u00ebr ju, dhe ju merrni gabime (avc\/denial) n\u00eb audit.log. Kur ndodh kjo, duhet t\u00eb krijoni nj\u00eb politik\u00eb lokale (Local policy). T\u00eb gjitha gabimet mund t\u2019i gjeni duke p\u00ebrdorur audit2why, si\u00e7 u p\u00ebrmend m\u00eb sip\u00ebr.<\/p>\n<p><\/p>\n<p>P\u00ebr t\u00eb eliminuar gabimet, mund t\u00eb krijoni nj\u00eb politik\u00eb lokale. P\u00ebr shembull, n\u00ebse marrim nj\u00eb gabim q\u00eb lidhet me httpd (apache) ose smbd (samba), ne grep\u2019ojm\u00eb gabimet dhe krijojm\u00eb nj\u00eb politik\u00eb p\u00ebr to:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">apache\n$ grep httpd_t \/var\/log\/audit\/audit.log | audit2allow -M http_policy\nsamba\n$ grep smbd_t \/var\/log\/audit\/audit.log | audit2allow -M smb_policy<\/code><\/pre>\n<p><\/p>\n<p>K\u00ebtu <code>http_policy<\/code> dhe <code>smb_policy<\/code> \u2014 jan\u00eb emrat e politikave lokale q\u00eb krijuam. Tani na nevojitet t\u00eb ngarkojm\u00eb k\u00ebto politika lokale t\u00eb krijuara n\u00eb politik\u00ebn aktuale SELinux. Kjo mund t\u00eb b\u00ebhet si m\u00eb posht\u00eb:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">$ semodule \u2013I http_policy.pp\n$ semodule \u2013I smb_policy.pp<\/code><\/pre>\n<p><\/p>\n<p>Politikat tona lokale u ngarkuan, dhe nuk duhet t\u00eb marrim m\u00eb ndonj\u00eb avc apo denial n\u00eb audit.log.<\/p>\n<p><em>Kjo ishte p\u00ebrpjekja ime p\u00ebr t'ju ndihmuar t\u00eb kuptoni SELinux. Shpresoj q\u00eb pas leximit t\u00eb k\u00ebtij artikulli t\u00eb ndiheni m\u00eb t\u00eb rehatsh\u00ebm me SELinux.<\/em><\/p>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/460387\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0435\u0440\u0435\u0432\u043e\u0434 \u0441\u0442\u0430\u0442\u044c\u0438 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d \u0434\u043b\u044f \u0441\u0442\u0443\u0434\u0435\u043d\u0442\u043e\u0432 \u043a\u0443\u0440\u0441\u0430 \u00ab\u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c Linux\u00bb SELinux \u0438\u043b\u0438 Security Enhanced Linux \u2014 \u044d\u0442\u043e \u0443\u043b\u0443\u0447\u0448\u0435\u043d\u043d\u044b\u0439 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u043e\u043c, \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043d\u043d\u044b\u0439 \u0410\u0433\u0435\u043d\u0442\u0441\u0442\u0432\u043e\u043c \u043d\u0430\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0421\u0428\u0410 (\u0410\u041d\u0411 \u0421\u0428\u0410) \u0434\u043b\u044f \u043f\u0440\u0435\u0434\u043e\u0442\u0432\u0440\u0430\u0449\u0435\u043d\u0438\u044f \u0437\u043b\u043e\u043d\u0430\u043c\u0435\u0440\u0435\u043d\u043d\u044b\u0445 \u0432\u0442\u043e\u0440\u0436\u0435\u043d\u0438\u0439. \u041e\u043d \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u0435\u0442 \u043f\u0440\u0438\u043d\u0443\u0434\u0438\u0442\u0435\u043b\u044c\u043d\u0443\u044e (\u0438\u043b\u0438 \u043c\u0430\u043d\u0434\u0430\u0442\u043d\u0443\u044e) \u043c\u043e\u0434\u0435\u043b\u044c \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u043e\u043c (\u0430\u043d\u0433\u043b. Mandatory Access Control, MAC) \u043f\u043e\u0432\u0435\u0440\u0445 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0435\u0439 \u0434\u0438\u0441\u043a\u0440\u0435\u0446\u0438\u043e\u043d\u043d\u043e\u0439 (\u0438\u043b\u0438 \u0438\u0437\u0431\u0438\u0440\u0430\u0442\u0435\u043b\u044c\u043d\u043e\u0439) \u043c\u043e\u0434\u0435\u043b\u0438 (\u0430\u043d\u0433\u043b. Discretionary Access Control, DAC), \u0442\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":27140,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-36280","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0435\u0440\u0435\u0432\u043e\u0434 \u0441\u0442\u0430\u0442\u044c\u0438 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d \u0434\u043b\u044f \u0441\u0442\u0443\u0434\u0435\u043d\u0442\u043e\u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/rukovodstvo-dlya-nachinayushhih-po-selinux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0443\u043a\u043e\u0432\u043e\u0434\u0441\u0442\u0432\u043e \u0434\u043b\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044e\u0449\u0438\u0445 \u043f\u043e SELinux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0435\u0440\u0435\u0432\u043e\u0434 \u0441\u0442\u0430\u0442\u044c\u0438 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d \u0434\u043b\u044f \u0441\u0442\u0443\u0434\u0435\u043d\u0442\u043e\u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/rukovodstvo-dlya-nachinayushhih-po-selinux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:10:39+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:10:39+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Guide p\u00ebr fillestar\u00ebt p\u00ebr SELinux | ProHoster","description":"P\u00ebrkthimi i artikullit \u00ebsht\u00eb p\u00ebrgatitur p\u00ebr student\u00ebt.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/rukovodstvo-dlya-nachinayushhih-po-selinux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0443\u043a\u043e\u0432\u043e\u0434\u0441\u0442\u0432\u043e \u0434\u043b\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044e\u0449\u0438\u0445 \u043f\u043e SELinux | ProHoster","og:description":"\u041f\u0435\u0440\u0435\u0432\u043e\u0434 \u0441\u0442\u0430\u0442\u044c\u0438 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d \u0434\u043b\u044f \u0441\u0442\u0443\u0434\u0435\u043d\u0442\u043e\u0432.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/rukovodstvo-dlya-nachinayushhih-po-selinux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:10:39+00:00","article:modified_time":"2019-10-31T19:10:39+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36280","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-09 15:05:39","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:47:35","updated":"2026-02-09 15:05:39","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/36280","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=36280"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/36280\/revisions"}],"predecessor-version":[{"id":158345,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/36280\/revisions\/158345"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/27140"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=36280"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=36280"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=36280"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}