ืื ืืืืขืจืืขืฆืื ื ืคืื ืืขื ืึทืจืืืงื ืืื ืืขืืืขื ืฆืืืขืืจืืื ืกืคึผืึทืกืืคืืงืื ืคึฟืึทืจ ืื ืกืืืืขื ืื ืคืื ืืขื ืงืืจืก
ืืึธ ืืืจ ืืืขื ืืึทืงืืืขื ืขื ืืคึฟืขืจืก ืฆื ืืืืืืืง ืคึฟืจืืื ืืืขืื ืืขืื, ืื ืึทืืืืขืื ืืื ืึทืืฅ ืืื ืืื ืืงืก ืืื ืืืคึผืจืืืื ืืืืขืจืืืื.
"ืื ืืืืืืืง ืืืช ืึทื ืื ืืื ืื ืืขื ืขื ื ืืฉื ืฉืืขื ืืืง ืืืึธืก ืืื ืืืกืงืืืขื ืืื ืคึผืจืึธืกื ืืืืกื ..."
-ืืึธืืืืึทืก ืึทืืึทืืก, ืื ืืืืฉืืืงืขืจ ืืืื ืฆื ืื ืืึทืืึทืงืกื
ืืืืขืจืงืืึทื. ืืขืืืืงืกื ืจืืืืืึทืืืืึทืื. ืืืืฉืืืืื ื. ืคึผืึธืืืืืง. ืคืืจ ืจืืืขืจืืึทื ืคืื ืื ืึทืคึผืึธืงืึทืืืคึผืกืข ืกืืกืึทืืืื. ืืื ืึทืืืฉืึทื ืฆื ืืื ืืืขืจ ืืขืืืขื ืืึทืกืงืก - ืืึธื ืืืึธืจืื ื, ืืึทืงืึทืคึผ, ืืืคึผืืึทืืขื ืืืืฉืึทื, ืงืึทื ืคืืืืขืจืืืฉืึทื, ืึทืคึผืืืืืื ื, ืืื"ื ื - ืืืจ ืืขื ืขื ืืืื ืคืึทืจืึทื ืืืืึธืจืืืขื ืคึฟืึทืจ ืื ืืืืขืจืืืื ืคืื ืืื ืืืขืจ ืกืืกืืขืืขื. ืืคืืื ืื ืกืืกืืขืืขื ืืื ืื ืืจืื-ืคึผืึทืจืืื ืฉืคึผืืึทืืขืจ ืจืขืงืึทืืขื ืื ืึทื ืืืจ ืืืกืืืืึทื ืขื ืืึทื ืกื ืืืืขืจืืืื. ืขืก ืคืืื ืืื ืึทืจืืขื
ืคืืืกื ืืื ืืขื ืืืืขืืึท, ืขืืืขืืข ืกืืกืืขื ืึทืืืื ืืกืืจืึทืืึธืจืก ืืึทืฉืืืกื ืฆื ื ืขืืขื
ืืื ืืขื ืืืืกื ืคืื ืื ืืืืฉืืืงืขืจ ืืืื ืฆื ืื ืืึทืืึทืงืกื, ืืึธ ืืขื ืขื 42 ืขื ืืคึฟืขืจืก ืฆื ืืืืืืืง ืคึฟืจืืื ืืืขืื ืงืึธื ืืจืึธื ืืื ื ืืฆื.
1. SELinux ืืื ืึท ืืขืฆืืืื ืืขื ืึทืงืกืขืก ืงืึธื ืืจืึธื ืกืืกืืขื, ืืืึธืก ืืืื ืึทื ืืขืืขืจ ืคึผืจืึธืฆืขืก ืืื ืึท ืคืืจืืข. ืืขืืขืจ ืืขืงืข, ืืืขืืืืืึทืืขืจ ืืื ืกืืกืืขื ืืืืคืขืฅ ืืืื ืืื ืืึทืืขืืก. ืคึผืึธืืืืืง ืึผืืืื ืงืึธื ืืจืึธืืืจื ืึทืงืกืขืก ืฆืืืืฉื ืืึทืื ืคึผืจืึทืกืขืกืึทื ืืื ืึทืืืืฉืขืงืฅ. ืืขืจ ืงืขืจื ืขื ืคืึธืจืกืื ืื ืึผืืืื.
2. ืื ืฆืืืื ืืขืจืกื ืืืืืืืง ืงืึทื ืกืขืคึผืก ืืขื ืขื: ืืืืืืื ื - ืืึทืจืงืื ืื (ืคืืืขืก, ืคึผืจืึทืกืขืกืึทื, ืคึผืึธืจืฅ, ืืื"ื ื) ืืื ืืืคึผ ืขื ืคืึธืจืกืืึทื ื (ืืืึธืก ืืืกืึทืืืืฅ ืคึผืจืึทืกืขืกืึทื ืคืื ืืขืืขืจ ืื ืืขืจืขืจ ืืืืืจื ืืืืฃ ืืืืคึผืก).
3. ืจืืืืืง ืคืืจืืข ืคึฟืึธืจืืึทื user:role:type:level
(ืึทืคึผืฉืึทื ืึทื).
4. ืืขืจ ืฆืื ืคืื ืฆืืฉืืขืื ืืึทืืื-ืืืจืื ืืืืขืจืืืื (ืืืืื-ืืขืืืขื ืืืืขืจืืืื - MLS) ืืื ืฆื ืคืืจื ืคึผืจืึทืกืขืกืึทื (ืืืืืื ื) ืืืืืจื ืืืืฃ ืื ืืืืขืจืืืื ืืืจืื ืคืื ืื ืืึทืื ืืื ืืืขืื ื ืืฆื. ืคึฟืึทืจ ืืืึทืฉืคึผืื, ืึท ืกืื ืคึผืจืึธืฆืขืก ืงืขื ื ืืฉื ืืืืขื ืขื ืฉืคึผืืฅ ืกืื ืืึทืื.
5. ืื ืฉืืจืื ื ืืึทืืื-ืงืืืขืืืจืืข ืืืืขืจืืืื (ืืืืื-ืงืืืขืืืจืืข ืืืืขืจืืืื - MCS) ืคึผืจืึทืืขืงืฅ ืขื ืืขื ืคึผืจืึทืกืขืกืึทื ืคืื ืืขืืขืจ ืื ืืขืจืขืจ (ืืืฉื, ืืืืจืืืึทื ืืืฉืื ืขื, OpenShift ืขื ืืืฉืึทื ื, SELinux ืืึทืืืืึธืงืกืขืก, ืงืึทื ืืืื ืขืจื, ืืื"ื ื).
6. ืงืขืจื ืขื ืึธืคึผืฆืืขืก ืคึฟืึทืจ ืืฉืึทื ืืื ื SELinux ืืึธืืขืก ืืื ืฉืืืืื:
autorelabel=1
โ ื ืื ืกืืกืืขื ืฆื ืืืืคื ืจืขืืึทืืขืืื ืselinux=0
โ ืืขืจ ืงืขืจื ืืื ื ืืฉื ืืึธืื ืื SELinux ืื ืคืจืึทืกืืจืึทืงืืฉืขืจenforcing=0
โ ืืึธืืืื ื ืืื ืคึผืขืจืืืกืืื ืืึธืืข
7. ืืืื ืืืจ ืืึทืจืคึฟื ืฆื ืจืืืืืื ืื ืืื ืฆืข ืกืืกืืขื:
# touch /.autorelabel
#reboot
ืืืื ืื ืกืืกืืขื ืืึทืจืงืื ื ืึผืืื ืึท ืืจืืืก ื ืืืขืจ ืคืื ืขืจืจืึธืจืก, ืืืจ ืงืขื ืืึทืจืคึฟื ืฆื ืฉืืืืื ืืื ืคึผืขืจืืืกืืื ืืึธืืข ืคึฟืึทืจ ืจืืืึทืจืงืื ื ืฆื ืืืื ืืขืจืึธืื.
8. ืฆื ืงืึธื ืืจืึธืืืจื ืืืื SELinux ืืื ืขื ืืืืึทืื: # getenforce
9. ืฆื ืืขืืคึผืขืจืขืจืึทืื ืืขืื / ืืืกืืืืึทื SELinux: # setenforce [1|0]
ืงืกื ืืืงืก. ืงืึธื ืืจืึธืืืจืื ื SELinux ืกืืึทืืืก: # sestatus
ืงืกื ืืืงืก. ืงืึธื ืคืืืืจืึทืืืึธื ืืขืงืข: /etc/selinux/config
ืงืกื ืืืงืก. ืืื ืึทืืื ืึทืจืืขื SELinux? ืืึธ ืืื ืึท ืืืืฉืคึผืื ืืึทืจืงืื ื ืคึฟืึทืจ ืื ืึทืคึผืึทืืฉื ืืืขื ืกืขืจืืืขืจ:
- ืืืื ืขืจื ืคืึทืจืืจืขืืื ื:
/usr/sbin/httpdโhttpd_exec_t
- ืงืึทื ืคืืืืขืจืืืฉืึทื ืืืขืืืืืึทืืขืจ:
/etc/httpdโhttpd_config_t
- ืงืืึธืฅ ืืขืงืข ืืืขืืืืืึทืืขืจ:
/var/log/httpd โ httpd_log_t
- ืืื ืืึทืื ืืืขืืืืืึทืืขืจ:
/var/www/html โ httpd_sys_content_t
- ืึธื ืืืื ืฉืจืืคื:
/usr/lib/systemd/system/httpd.service โ httpd_unit_file_d
- ืคึผืจืึธืฆืขืก:
/usr/sbin/httpd -DFOREGROUND โ httpd_t
- ืคืืจืืก:
80/tcp, 443/tcp โ httpd_t, http_port_t
ืคึผืจืึธืฆืขืก ืคืืืกื ืืืง ืืื ืงืึธื ืืขืงืกื httpd_t
, ืงืขื ืขื ืื ืืขืจืึทืงื ืืื ืึท ืืืืืึทืื ืืืืคืขืฅ httpd_something_t
.
ืงืกื ืืืงืก. ืคืืืข ืงืึทืืึทื ืื ืึธื ื ืขืืขื ืึท ืึทืจืืืืขื ื -Z
ืฆื ืืขื, ืฉืึทืคึฟื ืืื ืืืืฉื ืงืึธื ืืขืงืกื:
ls -Z
id -Z
ps -Z
netstat -Z
cp -Z
mkdir -Z
ืงืึธื ืืขืงืกืฅ ืืขื ืขื ืืขืืจืื ืืขื ืืืขื ืืขืงืขืก ืืขื ืขื ืืืฉืืคื ืืืืืจื ืืืืฃ ืืขื ืงืึธื ืืขืงืกื ืคืื ืืืืขืจ ืคืึธืืขืจ ืืืขืืืืืึทืืขืจ (ืืื ืขืืืขืืข ืืืืกื ืขืืขื). ืจืคึผื ืงืขื ืขื ืคืึทืจืืืืื ืงืึทื ืืขืงืกืฅ ืืื ืืขืฉืึทืก ืื ืกืืึทืืืจืื ื.
ืงืกื ืืืงืก. ืขืก ืืขื ืขื ืคืืจ ืืืืคึผื ืกืืืืช ืคืื SELinux ืขืจืจืึธืจืก, ืืืึธืก ืืขื ืขื ืืืกืงืจืืืื ืืื ืืขืจ ืืขืืึทื ืืื ืคืื ืงืื 15-21 ืืื ืื:
- ืืืืืืื ื ืืฉืื
- ืืืืึทื ืคืื ืขืคึผืขืก ืืืึธืก SELinux ืืึทืจืฃ ืืืืกื
- ืืขืืช ืืื SELinux ืคึผืึธืืืืืง / ืึทืคึผืืึทืงืืืฉืึทื
- ืืืื ืืื ืคึฟืึธืจืืึทืฆืืข ืงืขื ืืืื ืงืึทืืคึผืจืึทืืืืื
ืงืกื ืืืงืก. ืืืืืืื ื ืคึผืจืึธืืืขื: ืืืื ืืืื ืืขืงืขืก ืืขื ืขื ืืื /srv/myweb
ืืขื ืขื ื ืืฉื ืจืืืืืง ืื ืืขืฆืืืื ื, ืืขืจ ืฆืืืจืื ืงืขื ืืืื ืืขืืืืงื ื. ืืึธ ืืขื ืขื ืขืืืขืืข ืืืขืื ืฆื ืคืึทืจืจืืืื ืืขื:
- ืืืื ืืืจ ืืืืกื ืื ืคืืจืืข:
# semanage fcontext -a -t httpd_sys_content_t '/srv/myweb(/.*)?'
- ืืืื ืืืจ ืืืืกื ืึท ืืขืงืข ืืื ืขืงืืืืืืึทืืขื ื ืืึทืจืงืื ืื:
# semanage fcontext -a -e /srv/myweb /var/www
- ืจืืกืืึธืจืื ื ืืขื ืงืึธื ืืขืงืกื (ืคึฟืึทืจ ืืืืืข ืงืึทืกืขืก):
# restorecon -vR /srv/myweb
ืงืกื ืืืงืก. ืืืืืืื ื ืคึผืจืึธืืืขื: ืืืื ืืืจ ืืึทื ืื ืืขืงืข ืึทื ืฉืืึธื ืคืื ืงืึทืคึผืืื ื ืขืก, ืื ืืขืงืข ืืืขื ืจืืืืื ืืืื ืึธืจืืืื ืขื ืงืึธื ืืขืงืกื. ืฆื ืคืึทืจืจืืืื ืืขื ืคึผืจืึธืืืขื:
- ืืืืฉื ืื ืงืึธื ืืขืงืกื ืืึทืคึฟืขื ืืื ืื ืคืืจืืข:
# chcon -t httpd_system_content_t /var/www/html/index.html
- ืืืืฉื ืื ืงืึธื ืืขืงืกื ืืึทืคึฟืขื ืืื ืื ืืื ืง ืคืืจืืข:
# chcon --reference /var/www/html/ /var/www/html/index.html
- ืืืงืขืจื ืืขื ืงืึธื ืืขืงืกื (ืคึฟืึทืจ ืืืืืข ืงืึทืกืขืก):
# restorecon -vR /var/www/html/
ืงืกื ืืืงืก. ืฆื SELinux ืืืจ ืืึทืจืคึฟื ืฆื ืืืืกืืึทื HTTPD ืืื ืฆืืืขืืขืจื ืืืืฃ ืคึผืึธืจื 8585, ืืึธืื SELinux:
# semanage port -a -t http_port_t -p tcp 8585
ืงืกื ืืืงืก. SELinux ืืืจ ืืึทืจืคึฟื ืฆื ืืืืกื ืืึธืึธืืขืึทื ืืืึทืืืขืก ืืืึธืก ืืึธืื ืืืืื ืคืื ืื SELinux ืคึผืึธืืืืืง ืฆื ืืืื ืืฉืืื ืืืฉื ืืื ืจืื ืืืืข ืึธื ืืืืกื ืคืื ืื SELinux ืคึผืึธืืืืืง ืืื ืึธืืืืขืจืจืืืึทื. ืคึฟืึทืจ ืืืึทืฉืคึผืื, ืืืื ืืืจ ืืืืื httpd ืฆื ืฉืืงื ืืืืฆืคึผืึธืกื, ืึทืจืืึทื: # setsebool -P httpd_can_sendmail 1
ืงืกื ืืืงืก. SELinux ืืืจ ืืึทืจืคึฟื ืฆื ืืืืกื ืืึทืืืฉืืงืึทื ืืืึทืืืขืก ืคึฟืึทืจ ืขื ืืืืึทืืื ื / ืืืกืืืืึทื SELinux ืกืขืืืื ืืก:
- ืฆื ืืขื ืึทืืข ืืืืืึทื ืืืึทืืืขืก:
# getsebool -a
- ืฆื ืืขื ืึท ืืึทืฉืจืืึทืืื ื ืคืื ืืขืืขืจ:
# semanage boolean -l
- ืฆื ืฉืืขืื ืึท ืืืืืึทื ืืืขืจื:
# setsebool [_boolean_] [1|0]
- ืคึฟืึทืจ ืึท ืฉืืขื ืืืง ืืึทื ืืึธื ืืืจืื ื, ืืืืื
-P
. ืฆืื ืืืืฉืคึผืื:# setsebool httpd_enable_ftp_server 1 -P
ืงืกื ืืืงืก. SELinux ืคึผืึทืืึทืกืื / ืึทืคึผืืึทืงืืืฉืึทื ื ืงืขื ืึทื ืืืึทืืื ืขืจืจืึธืจืก, ืึทืจืืึทื ืืขืจืขืื ื:
- ืืืืขืืืืื ืืืขื ืงืึธื ืคึผืึทืืก
- ืงืึธื ืคืืืืจืึทืืืึธื ืก
- ืจืืืขืจืขืงืืื ื ืกืืืึธืื
- ืืขืงืข ืืืกืงืจืืคึผืืึธืจ ืืืงืก
- ืขืงืกืขืงืืืึทืืืข ืืึผืจืื
- ืฉืืืึทื ืืขืืืื ืืืืืืึธืืขืง
ืขืคึฟืขื ืขื ืืืงืืฅ (ืืึธื ื ืื ืคืึธืจืืืืื ืึท ืืึทืจืืื ืฆื Bugzilla; Bugzilla ืืื ืงืืื SLA).
ืงืกื ืืืงืก. ืืืื ืืื ืคึฟืึธืจืืึทืฆืืข ืงืขื ืืืื ืงืึทืืคึผืจืึทืืืืืืืืื ืืืจ ืืึธืื ืืืืืืขื ืืึธืืืืื ื ืืจืืื ื ืฆื:
- ืืึธืื ืงืขืจื ืืึทืืืฉืืื
- ืืืกืืืืึทื ืขื ืคืึธืจืกื SELinux ืืึธืืข
- ืฉืจืืื ืฆื
etc_t/shadow_t
- ืืืืฉื ืื ืึผืืืื ืคืื ืืคึผืืึทืืืขืก
ืงืกื ืืืงืก. SELinux ืืืฉืืจืื ืคึฟืึทืจ ืืขืืืขืืึธืคึผืื ื ืคึผืึธืืืืืง ืืึทืืืฉืืื:
# yum -y install setroubleshoot setroubleshoot-server
ืจืขืืึธืึธื ืึธืืขืจ ืจืืกืืึทืจื auditd
ื ืึธื ืืึทื ืืึธื ืืืจืื ื.
ืงืกื ืืืงืก. ื ืืฆื
journalctl
ืฆื ืืืืึทืื ืึท ืจืฉืืื ืคืื ืึทืืข ืืึธืืก ืคึฟืึทืจืืื ืื ืืื setroubleshoot
:
# journalctl -t setroubleshoot --since=14:20
ืงืกื ืืืงืก. ื ืืฆื journalctl
ืฆื ืจืฉืืื ืึทืืข ืืึธืืก ืคึฟืึทืจืืื ืื ืืื ืึท ืกืคึผืขืฆืืคืืฉ SELinux ืงืืืืื. ืืืฉื:
# journalctl _SELINUX_CONTEXT=system_u:system_r:policykit_t:s0
ืงืกื ืืืงืก. ืืืื ืึท SELinux ืืขืืช ืึทืงืขืจื, ื ืืฆื ืื ืงืืึธืฅ setroubleshoot
ืคืึธืจืฉืืึธืื ืขืืืขืืข ืืขืืืขื ืกืึทืืืฉืึทื ื.
ืคึฟืึทืจ ืืืึทืฉืคึผืื, ืคึฟืื journalctl
:
Jun 14 19:41:07 web1 setroubleshoot: SELinux is preventing httpd from getattr access on the file /var/www/html/index.html. For complete message run: sealert -l 12fd8b04-0119-4077-a710-2d0e0ee5755e
# sealert -l 12fd8b04-0119-4077-a710-2d0e0ee5755e
SELinux is preventing httpd from getattr access on the file /var/www/html/index.html.
***** Plugin restorecon (99.5 confidence) suggests ************************
If you want to fix the label,
/var/www/html/index.html default label should be httpd_syscontent_t.
Then you can restorecon.
Do
# /sbin/restorecon -v /var/www/html/index.html
ืงืกื ืืืงืก. ืืึธืืื ื: SELinux ืจืขืงืึธืจืืืจื โโืืื ืคึฟืึธืจืืึทืฆืืข ืืื ืคืืืข ืขืจืืขืจ:
- / ืืืึทืจ / ืงืืึธืฅ / ืึทืจืืืงืืขื
- /var/log/audit/audit.log
- /var/lib/setroubleshoot/setroubleshoot_database.xml
ืงืกื ืืืงืก. ืืึธืืื ื: ืืืื ืคึฟืึทืจ SELinux ืขืจืจืึธืจืก ืืื ืื ืงืึธื ืืจืึธืืืจื ืงืืึธืฅ:
# ausearch -m AVC,USER_AVC,SELINUX_ERR -ts today
ืงืกื ืืืงืก. ืฆื ืืขืคึฟืื ืขื SELinux ืึทืงืกืขืก ืืืขืงืืึธืจ ืงืึทืฉ (AVC) ืึทืจืืืงืืขื ืคึฟืึทืจ ืึท ืกืคึผืขืฆืืคืืฉ ืืื ืกื:
# ausearch -m avc -c httpd
ืงืกื ืืืงืก. ื ืืฆื audit2allow
ืงืึทืืขืงืฅ ืืื ืคึฟืึธืจืืึทืฆืืข ืคืื โโืืึธืืก ืคืื ืคึผืจืึธืืืืืึทืืึทื ืึทืคึผืขืจืืืฉืึทื ื ืืื ืืืฉืขื ืขืจืืืฅ SELinux ืืขืจืืืืืขื ืืฉ ืคึผืึธืืืืืง ืึผืืืื. ืืืฉื:
- ืฆื ืฉืึทืคึฟื ืึท ืืขื ืืฉ-ืืืื ืขืืืืืง ืืึทืฉืจืืึทืืื ื ืคืื ืืืึธืก ืึทืงืกืขืก ืืื ืืขืืืืงื ื:
# audit2allow -w -a
- ืฆื ืืขื ืึท ืืืคึผ ืขื ืคืึธืจืกืืึทื ื ืืขืจืฉื ืืืึธืก ืึทืืึทืื ืืขืืืืงื ื ืึทืงืกืขืก:
# audit2allow -a
- ืฆื ืฉืึทืคึฟื ืึท ืื ืื ืืึธืืืืข:
# audit2allow -a -M mypolicy
- ืึธืคึผืฆืืข
-M
ืงืจืืืืฅ ืึท ืืืคึผ ืขื ืคืึธืจืกืืึทื ื ืืขืงืข (.ืืข) ืืื ืื ืกืคึผืขืกืึทืคืืื ื ืึธืืขื ืืื ืงืึทืืคึผืืืื ืื ืืขืจืฉื ืืื ืึท ืคึผืึธืืืืืง ืคึผืขืงื (.ืคึผืคึผ):mypolicy.pp mypolicy.te
- ืฆื ืื ืกืืึทืืืจื ืึท ืื ืื ืืึธืืืืข:
# semodule -i mypolicy.pp
ืงืกื ืืืงืก. ืฆื ืงืึทื ืคืืืืขืจ ืึท ืืึทืืื ืืขืจ ืคึผืจืึธืฆืขืก ( ืคืขืื) ืฆื ืึทืจืืขืื ืืื ืคึผืขืจืืืกืืื ืืึธืืข: # semanage permissive -a httpd_t
ืงืกื ืืืงืก. ืืืื ืืืจ ื ืื ืืขืจ ืืืืื ืื ืคืขืื ืฆื ืืืื ืคึผืขืจืืืกืืื: # semanage permissive -d httpd_t
ืงืกื ืืืงืก. ืฆื ืืืกืืืืึทื ืึทืืข ืคึผืขืจืืืกืืื ืืึธืืืืื ื: # semodule -d permissivedomains
ืงืกื ืืืงืก. ืขื ืืืืึทืืื ื MLS SELinux ืคึผืึธืืืืืง: # yum install selinux-policy-mls
ะฒ /etc/selinux/config:
SELINUX=permissive
SELINUXTYPE=mls
ืืึทืื ืืืืขืจ ืึทื SELinux ืืื ืคืืืกื ืืืง ืืื ืคึผืขืจืืืกืืื ืืึธืืข: # setenforce 0
ื ืืฆื ืึท ืฉืจืืคื fixfiles
ืฆื ืขื ืฉืืจ ืึทื ืื ืืขืงืขืก ืืขื ืขื ืจืขืืึทืืขืืขื ืืืืฃ ืืขืจ ืืืืึทืืขืจ ืจืขืืึธืึธื:
# fixfiles -F onboot # reboot
ืงืกื ืืืงืก. ืฉืึทืคึฟื ืึท ืืึทื ืืฆืขืจ ืืื ืึท ืกืคึผืขืฆืืคืืฉ MLS ืงืืื: # useradd -Z staff_u john
ื ืืฆื ืื ืืึทืคึฟืขื useradd
, ืืึทืคึผืข ืื ื ืืึทืข ืืึทื ืืฆืขืจ ืฆื ืึทื ืืืืืกืืื ื SELinux ืืึทื ืืฆืขืจ (ืืื ืืขื ืคืึทื, staff_u
).
ืงืกื ืืืงืก. ืฆื ืืขื ืื ืืึทืคึผืื ื ืฆืืืืฉื SELinux ืืื Linux ื ืืฆืขืจืก: # semanage login -l
ืงืกื ืืืงืก. ืืขืคืื ืืจื ืึท ืกืคึผืขืฆืืคืืฉ ืงืืื ืคึฟืึทืจ ืื ืืึทื ืืฆืขืจ: # semanage login --modify --range s2:c100 john
ืงืกื ืืืงืก. ืฆื ืคืึทืจืจืืืื ืืขื ืืึทื ืืฆืขืจ 'ืก ืืืื ืืืขืืืืืึทืืขืจ ืคืืจืืข (ืืืื ื ืืืืืง): # chcon -R -l s2:c100 /home/john
ืงืกื ืืืงืก. ืฆื ืืขื ืงืจืึทื ื ืงืึทืืขืืึธืจืืขืก: # chcat -L
ืงืกื ืืืงืก. ืฆื ืืืืฉื ืงืึทืืขืืึธืจืืขืก ืึธืืขืจ ืึธื ืืืืื ืงืจืืืืืื ื ืืืื ืืืืืขื ืข, ืจืขืืึทืืืจื ืื ืืขืงืข ืืื ืืืื:
/etc/selinux/_<
selinuxtype>
_/setrans.conf
ืงืกื ืืืงืก. ืฆื ืืืืคื ืึท ืืึทืคึฟืขื ืึธืืขืจ ืฉืจืืคื ืืื ืึท ืกืคึผืขืฆืืคืืฉ ืืขืงืข, ืจืึธืืข ืืื ืืึทื ืืฆืขืจ ืงืึธื ืืขืงืกื:
# runcon -t initrc_t -r system_r -u user_u yourcommandhere
-t
ืืขืงืข ืงืึธื ืืขืงืกื-r
ืจืึธืืข ืงืึธื ืืขืงืกื-u
ืืึทื ืืฆืขืจ ืงืึธื ืืขืงืกื
ืงืกื ืืืงืก. ืงืึทื ืืืื ืขืจื ืืื SELinux ืคืึทืจืงืจืืคึผืื:
- ืคืืืืื:
# podman run --security-opt label=disable โฆ
- ืืึธืงืงืขืจ:
# docker run --security-opt label=disable โฆ
ืงืกื ืืืงืก. ืืืื ืืืจ ืืึทืจืคึฟื ืฆื ืืขืื ืืขื ืงืึทื ืืืื ืขืจ ืคืื ืึทืงืกืขืก ืฆื ืื ืกืืกืืขื:
- ืคืืืืื:
# podman run --privileged โฆ
- ืืึธืงืงืขืจ:
# docker run --privileged โฆ
ืืื ืืืฆื ืืืจ ืฉืืื ืืืืกื ืื ืขื ืืคืขืจ. ืึทืืื ืืืืข: ืืึธื ื ืื ืคึผืึทื ืืง ืืื ืืขืื SELinux.
ืืื ืงืก:
SELinux byืื ืืืืืฉ ืืืื ืืืืืฉืึทืืืึทื ืืื-ืฆื ืคืืจื ืคึฟืึทืจ SELinux ืคึผืึธืืืืืง ืขื ืคืึธืจืกืืึทื ื ืืืื ืืืจื ืื ืืืึทืืฉืืืืขืจืืืื ืขื ืืึทื ืกื ืืื ืืงืก ืคึฟืึทืจ ืืืืื ืืึธืจืืึทืื byืืืืขืก ืงืึทืืขืจืึธื ืื ืกืขืืื ืืงืก ืงืึธืืึธืจืื ื ืกืคืจ byืืืืจืื ืืืคื SELinux ืืึทื ืืฆืขืจ ืืื ืึทืืืื ืืกืืจืึทืืึธืจ ืก ืืืื - Red Hat Enterprise Linux 7
ืืงืืจ: www.habr.com