Your support on Ko-Fi is much appreciated:
👉 https://ko-fi.com/csg_yt
Join our new discord channel:
👉 / discord
Buy CSG Merchandise:
👉 http://tee.pub/lic/csg
This video is based on RHEL 8.
Video to cover the section 'List and identify SELinux file and process context' for the RHCSA (Red Hat Certified System Administrator).
More information on the required learning: http://bit.ly/rhcsa8
Notes from the video:
SELinux defines access controls for the applications, processes, and files on a system. It uses security policies, which are a set of rules that tell SELinux what can or can’t be accessed, to enforce the access allowed by a policy.
When an application or process, known as a subject, makes a request to access an object, like a file, SELinux checks with an access vector cache (AVC), where permissions are cached for subjects and objects.
If SELinux is unable to make a decision about access based on the cached permissions, it sends the request to the security server. The security server checks for the security context of the app or process and the file. Security context is applied from the SELinux policy database. Permission is then granted or denied.
If permission is denied, an “avc: denied” message will be available in /var/log/messages.
SELinux had a large number of the contexts already defined, for example the type context is defined for already for processes such as ssh.
To view the context of all files or folders in a particular directory use:
ls -Z
To view the context of all processes running on the system run:
ps -Zaux
Note to view the current processes for just this shell run:
ps -Z
To view your user contexts run:
id -Z
#rhcsa #rhel #linux #redhat