lmi
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [lmi] ZOMG selinux


From: Greg Chicares
Subject: Re: [lmi] ZOMG selinux
Date: Mon, 1 Nov 2021 20:47:43 +0000
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.13.0

On 10/31/21 3:46 PM, Vadim Zeitlin wrote:
> 
> [...] in fact, I'm not
> even sure if SELinux is enabled for you (what does "getenforce" output?),

/srv/cache_for_lmi/logs[0]$getenforce
Permissive

$ sestatus
SELinux status:                 enabled
SELinuxfs mount:                /sys/fs/selinux
SELinux root directory:         /etc/selinux
Loaded policy name:             targeted
Current mode:                   permissive
Mode from config file:          permissive
Policy MLS status:              enabled
Policy deny_unknown status:     allowed
Max kernel policy version:      31

Maybe I should try turning it on:
  sudo sestatus enforcing
just to see what happens. Presumably someday they'll switch it to
enforcing mode, with no prior notice, and it'll probably be easier
to protect against that now than to recover from it later.


reply via email to

[Prev in Thread] Current Thread [Next in Thread]