7.0 SELinux

Topics

  • Selinux basics

  • Semanage

  • Secontext

  • Sealert

  • SeBoolean

Reading List

Chapter: 22

Commands

Command

Action

getenforce

show status of selinux

setenforce

set non permanent status of selinux

semanage

change selinux policies (port, context, boolean)

chcon

change selinux context

restorecon

restore selinux context

sealert

show selinux alerts from specified file

getsebool

get selinux boolean

setsebool

set selinux boolean

Config Files

File

Config

/etc/selinux/config

has the permanent status of selinux