/etc/security/limits.conf #定义对用户的各种限制
#<domain> <type> <item> <value> #具体文件中有定义user4 hard Nofile #限制user4最多打 Open 10 files User5 hard as 10240 #限制user5只能使用10M内存
MAC: Mandatory access control. Added control of the application.
/etc/selinux/config #配置文件
# this file controls the state of selinux on the system.# SELINUX= can take one of these three values: #3种工作模式 # enforcing - selinux security policy is enforced. #强制模式 # permissive - selinux prints warnings instead of enforcing. #警告模式 # disabled - no selinux policy is loaded. selinux=enforcing# selinuxtype= can take one of these two values:# targeted - targeted processes are protected, # Do not restrict local users and services, only restrict network users # minimum - modification of targeted policy. only selected processes are protected. # Mls - multi&nBsp level security protection. #最高的保护级别. #如果要使用此级别需要安装一个包. Selinux-policy-mls. selinuxtype=targeted
Under mandatory mode, the SELinux policy is in effect
Under warning mode, SELinux does not disable the policy, but it logs a warning message.
Switching from enforcing to permissive does not require a reboot, and all others require a reboot. Switch to permissive more for troubleshooting.
[Email protected] ~]# getenforce #查看目前处于什么模式下Enforcing [[email protected] ~]# Setenforce 0 #切换到permissive模式0: Per Missive Mode 1:disable mode
SELinux Course Content