updated notes
This commit is contained in:
@@ -601,4 +601,56 @@ chattr +a /etc/passwd # Set the append only attribute on the /etc/passwd file
|
||||
|
||||
chattr -i /etc/passwd # Remove the immutable attribute on the /etc/passwd file
|
||||
chattr -R -i /etc/ # Remove the immutable attribute on the /etc/ directory and all its contents
|
||||
```
|
||||
|
||||
### getfacl
|
||||
```bash
|
||||
getfacl /etc/passwd # Display the ACLs of the /etc/passwd file
|
||||
```
|
||||
|
||||
### setfacl
|
||||
```bash
|
||||
setfacl -m u:user:rwx /etc/passwd # Set the ACLs of the /etc/passwd file for the user user with read, write, and execute permissions
|
||||
setfacl -m g:group1:r file.txt # Set the ACLs of the file.txt file for the group group1 read only
|
||||
```
|
||||
|
||||
### SELinux Basics
|
||||
```bash
|
||||
sudo sestatus # Display the SELinux status
|
||||
|
||||
sudo getenforce # Display the SELinux mode
|
||||
|
||||
sudo setenforce 0 # Set the SELinux mode to permissive
|
||||
sudo setenforce 1 # Set the SELinux mode to enforcing
|
||||
|
||||
ls -Z # List the SELinux context of the files and directories
|
||||
ps -eZ # List the SELinux context of the processes
|
||||
|
||||
### SELinux Port Management
|
||||
# Note: SELinux will block any attempt to use a port that is not in the SELinux policy in enforcing mode.
|
||||
sudo semanage port -a -t http_port_t -p tcp 8080 # Add the HTTP port to the SELinux policy
|
||||
sudo semanage port -d -t http_port_t -p tcp 8080 # Remove the HTTP port from the SELinux policy
|
||||
|
||||
### SELinux Login Management
|
||||
sudo semanage login -a -s user_t user1 # Add the user user1 to the SELinux policy
|
||||
sudo semanage login -d user1 # Remove the user user1 from the SELinux policy
|
||||
|
||||
### getsebool
|
||||
```bash
|
||||
getsebool -a # List all SELinux booleans
|
||||
|
||||
getsebool httpd_can_network_connect # Display the SELinux boolean for the httpd_can_network_connect boolean
|
||||
|
||||
### setsebool
|
||||
```bash
|
||||
setsebool -P httpd_can_network_connect on # Set the httpd_can_network_connect boolean to on
|
||||
setsebool -P httpd_can_network_connect off # Set the httpd_can_network_connect boolean to off
|
||||
|
||||
sudo semanage boolean -l -C # List all SELinux booleans
|
||||
|
||||
### sealert
|
||||
```bash
|
||||
sudo sealert -a /var/log/audit/audit.log # Display the SELinux alerts
|
||||
|
||||
journalctl | grep -i sealert # Display the SELinux alerts
|
||||
```
|
||||
Reference in New Issue
Block a user