一些關於sulinux的知識

來源:互聯網
上載者:User
在Redhat Enterprise Linux 4.0或Fedora Core 2 Linux以 上版本的Linux中,有不少使用者經常會遇到諸如apache的Permission denied,X windows打不開等等問題,拋開一些常規配 置錯誤外,很大一部分原因是因為啟用了SELinux的緣故。

什麼是SELinux?SELinux全稱是 Security Enhanced Linux,由美國國家安全部(National Security Agency)領導開發的GPL項目,它擁有 一個靈活而強制性的存取控制結構,旨在提高Linux系統的安全性,提供強健的安全保證,可防禦未知攻擊,據稱相當於B1級的軍事安全效能。比MS NT 所謂的C2等高得多。

應用SELinux後,可以減輕惡意攻擊或惡意軟體帶來的災難,並提供對機密性和完整性有很高要求的資訊很高的安全保障。

SELinux vs Linux
普 通Linux安全和傳統Unix系統一樣,基於自主存取控制方法,即DAC,只要符合規定的許可權,如規定的所有者和檔案屬性等,就可存取資源。在傳統的安 全機制下,一些通過setuid/setgid的程式就產生了嚴重安全隱患,甚至一些錯誤的配置就可引發巨大的漏洞,被輕易攻擊。

而SELinux則基於強制存取控制方法,即MAC,透過強制性的安全性原則,應用程式或使用者必須同時符合DAC及對應SELinux的MAC才能進行正常操作,否則都將遭到拒絕或失敗,而這些問題將不會影響其他正常運作的程式和應用,並保持它們的安全系統結構。

SELinux on Redhat Linux
在RHEL4.0或FC3以上的版本中,可以在安裝時就選擇是否啟用SELinux,系統自動會安裝相應的核心、工具、程式等。由於SELinux的MAC機制將極大的影響了現有引用,因此RHEL4/FC3中已預配置了大量相容現有應用的安全性原則。

SELinux的配置相關檔案都在/etc/selinux下,其中/etc/selinux/targeted目錄裡就包含了策略的詳細配置和context定義,以下是主要檔案及功用:
/etc/selinux/targeted/contexts/*_context 預設的context設定
/etc/selinux/targeted/contexts/files/* 精確的context類型劃分
/etc/selinux/targeted/policy/* 策略檔案

-----------------------------------------------
Q:  How do I turn SELinux off at boot?  
A: Set SELINUX=disabled in /etc/selinux/config. 

Alternatively, you can add selinux=0 to your kernel boot parameters. However, this option is not recommended. 
      Be careful when disabling SELinux 
If you boot with selinux=0, any files you create while SELinux is disabled do not have SELinux context information. The file system is marked for relabeling at the next boot. If an unforeseen problem prevents you from rebooting normally, you may need to boot in single-user mode for recovery. Add the option emergency to your kernel boot parameters. 

Q:  How do I turn enforcing on/off at boot? 
A: You can specify the SELinux mode using the configuration file /etc/sysconfig/selinux. 
# This file controls the state of SELinux on the system.
# SELINUX= can take one of these three values:
#       enforcing - SELinux security policy is enforced.
#       permissive - SELinux prints warnings instead of enforcing.
#       disabled - No SELinux policy is loaded.
SELINUX=enforcing
# SELINUXTYPE= type of policy in use. Possible values are:
#       targeted - Only targeted network daemons are protected.
#       strict - Full SELinux protection.
SELINUXTYPE=targeted
  However, setting the value to disabled is not the same as the selinux=0 kernel boot parameter. Rather than fully disabling SELinux in the kernel, the disabled setting instead turns enforcing off and skips loading a policy. 

相關網址:http://fedora.redhat.com/docs/selinux-faq-fc5/#id2962490

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.