5 ms·
The targeted policies and functionality booleans in CentOS are really nice. I took the same step with finally buckling down and actually using SELinux for versi
by dice 10y ago
The targeted policies and functionality booleans in CentOS are really nice. I took the same step with finally buckling down and actually using SELinux for version 6 and there was definitely a learning cliff, but just like anything else after you've used it for a while it's all old hat.
You may have seen it already, but the CentOS SELinux HOWTO was very useful for me in learning how to interact with it: https://wiki.centos.org/HowTos/SELinux https://wiki.centos.org/HowTos/SELinux
>Turns out that doing crazy shit like letting users have their html files in ~/public_html/ requires a lot of SELinux configuration
You should just be able to `setsebool httpd_enable_homedirs on`. What trouble did you run in to?
>procmail touching user directories?
This works by default for me in in C6 and C7: I'm using it on a number of production systems. The ~/.procmailrc should have type procmail_home_t but procmail itself can create/modify/delete files in the user's home dir.
>spamassassin?
Again, should just work. You may need to `setsebool spamassassin_can_network on` depending on configuration.
>a tool which tells you what new rules are needed
That would be nice. My usual process if I'm in a situation that needs custom rules is to:
echo '' >/var/log/audit/audit.log # (it would be better to rotate it here, but you get the idea)
setenforce 0
# Do whatever I want to be able to do...
setenforce 1
sealert -a /var/log/audit/audit.log
- greglindahl 10y agoI read that HOWTO, actually, and the stuff you're describing isn't really explained in it. For example, there's a httpd example changing a label right there in the HOWTO, and it doesn't explain where I'm supposed to discover the correct label. And the recommended audit-script-to-config doesn't show the correct labels, it prompts you to relax the rule instead of changing labels. My procmail rules don't correspond to what you said procmail does. And how was I supposed to discover procmail_home_t ? I'm not saying I'm Mr. Super Smart, I'm just saying that it's quite a bit of investment.
- jamble 10y ago> I read that HOWTO, actually, and the stuff you're describing isn't really explained in it. Did you read this part? It explains a solution to your first gripe: https://wiki.centos.org/HowTos/SELinux#head-0f6390ddacfab39ee973ed8018a32212c2a02199 https://wiki.centos.org/HowTos/SELinux#head-0f6390ddacfab39e... I find audit2why helpful, as well as semanage boolean -l, semanage user -l, semanage fcontext -l. Often times more than not, these tools either help me fix an 'audit' issue or point me in the right direction. Check them out sometime, if you don't want to go digging through docs or serverfault - the labels tend to be generally straight forward IMO :-)
- nnutter 10y agoThe man pages are useful, especially once you know the basics. For example, start at [man selinux](http://linux.die.net/man/8/selinux http://linux.die.net/man/8/selinux) in See Also see the reference to [man httpd_selinux](http://linux.die.net/man/8/httpd_selinux http://linux.die.net/man/8/httpd_selinux) and in there you find every type and boolean including `httpd_enable_homedirs`. See also, [man procmail_selinux](http://linux.die.net/man/8/procmail_selinux http://linux.die.net/man/8/procmail_selinux).
- emmelaich 10y agoYou'll have to add a -P to `setsebool httpd_enable_homedirs on` to be super-effective. Which sorta supports the OP's point. The -P means persist through a reboot.