码迷,mamicode.com
首页 > 系统相关 > 详细

Centos 7/8 SELinux

时间:2020-03-14 10:43:38      阅读:122      评论:0      收藏:0      [点我收藏+]

标签:obj   get   开放   fine   tor   version   use   状态   ade   

SELinux介绍

  1.端口防护

  2.文件防护

  3.服务防护

  4.selinux性能影响

  

 

selinux配置文件

  /etc/selinux/config

 

selinux状态查看

[root@centos ~]# sestatus -v
SELinux status:                 enabled
SELinuxfs mount:                /sys/fs/selinux
SELinux root directory:         /etc/selinux
Loaded policy name:             targeted
Current mode:                   enforcing
Mode from config file:          enforcing
Policy MLS status:              enabled
Policy deny_unknown status:     allowed
Memory protection checking:     actual (secure)
Max kernel policy version:      31

Process contexts:
Current context:                unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
Init context:                   system_u:system_r:init_t:s0
/sbin/agetty                    system_u:system_r:getty_t:s0-s0:c0.c1023
/usr/sbin/sshd                  system_u:system_r:sshd_t:s0-s0:c0.c1023

File contexts:
Controlling terminal:           unconfined_u:object_r:user_devpts_t:s0
/etc/passwd                     system_u:object_r:passwd_file_t:s0
/etc/shadow                     system_u:object_r:shadow_t:s0
/bin/bash                       system_u:object_r:shell_exec_t:s0
/bin/login                      system_u:object_r:login_exec_t:s0
/bin/sh                         system_u:object_r:bin_t:s0 -> system_u:object_r:shell_exec_t:s0
/sbin/agetty                    system_u:object_r:getty_exec_t:s0
/sbin/init                      system_u:object_r:bin_t:s0 -> system_u:object_r:init_exec_t:s0
/usr/sbin/sshd                  system_u:object_r:sshd_exec_t:s0

 

selinux端口开放

  semanage 

 

selinux服务开放

  semanage

 

Centos 7/8 SELinux

标签:obj   get   开放   fine   tor   version   use   状态   ade   

原文地址:https://www.cnblogs.com/vincenshen/p/12490654.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!