[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [lmi] ZOMG selinux
From: |
Greg Chicares |
Subject: |
Re: [lmi] ZOMG selinux |
Date: |
Mon, 1 Nov 2021 20:47:43 +0000 |
User-agent: |
Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.13.0 |
On 10/31/21 3:46 PM, Vadim Zeitlin wrote:
>
> [...] in fact, I'm not
> even sure if SELinux is enabled for you (what does "getenforce" output?),
/srv/cache_for_lmi/logs[0]$getenforce
Permissive
$ sestatus
SELinux status: enabled
SELinuxfs mount: /sys/fs/selinux
SELinux root directory: /etc/selinux
Loaded policy name: targeted
Current mode: permissive
Mode from config file: permissive
Policy MLS status: enabled
Policy deny_unknown status: allowed
Max kernel policy version: 31
Maybe I should try turning it on:
sudo sestatus enforcing
just to see what happens. Presumably someday they'll switch it to
enforcing mode, with no prior notice, and it'll probably be easier
to protect against that now than to recover from it later.
- Re: [lmi] ZOMG selinux,
Greg Chicares <=