From 0add4424e85550cf9fd15c01d72b6994df18bb9f Mon Sep 17 00:00:00 2001 From: Hugh Ratsch Date: Sun, 16 Feb 2025 23:03:05 -0600 Subject: [PATCH] updated notes --- src/rhcsa.md | 52 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) diff --git a/src/rhcsa.md b/src/rhcsa.md index ec8125f..3b717d4 100644 --- a/src/rhcsa.md +++ b/src/rhcsa.md @@ -601,4 +601,56 @@ chattr +a /etc/passwd # Set the append only attribute on the /etc/passwd file chattr -i /etc/passwd # Remove the immutable attribute on the /etc/passwd file chattr -R -i /etc/ # Remove the immutable attribute on the /etc/ directory and all its contents +``` + +### getfacl +```bash +getfacl /etc/passwd # Display the ACLs of the /etc/passwd file +``` + +### setfacl +```bash +setfacl -m u:user:rwx /etc/passwd # Set the ACLs of the /etc/passwd file for the user user with read, write, and execute permissions +setfacl -m g:group1:r file.txt # Set the ACLs of the file.txt file for the group group1 read only +``` + +### SELinux Basics +```bash +sudo sestatus # Display the SELinux status + +sudo getenforce # Display the SELinux mode + +sudo setenforce 0 # Set the SELinux mode to permissive +sudo setenforce 1 # Set the SELinux mode to enforcing + +ls -Z # List the SELinux context of the files and directories +ps -eZ # List the SELinux context of the processes + +### SELinux Port Management +# Note: SELinux will block any attempt to use a port that is not in the SELinux policy in enforcing mode. +sudo semanage port -a -t http_port_t -p tcp 8080 # Add the HTTP port to the SELinux policy +sudo semanage port -d -t http_port_t -p tcp 8080 # Remove the HTTP port from the SELinux policy + +### SELinux Login Management +sudo semanage login -a -s user_t user1 # Add the user user1 to the SELinux policy +sudo semanage login -d user1 # Remove the user user1 from the SELinux policy + +### getsebool +```bash +getsebool -a # List all SELinux booleans + +getsebool httpd_can_network_connect # Display the SELinux boolean for the httpd_can_network_connect boolean + +### setsebool +```bash +setsebool -P httpd_can_network_connect on # Set the httpd_can_network_connect boolean to on +setsebool -P httpd_can_network_connect off # Set the httpd_can_network_connect boolean to off + +sudo semanage boolean -l -C # List all SELinux booleans + +### sealert +```bash +sudo sealert -a /var/log/audit/audit.log # Display the SELinux alerts + +journalctl | grep -i sealert # Display the SELinux alerts ``` \ No newline at end of file