3 ms·
For some distributions, CIS benchmarks (also used by various other security tools) now include guidelines for SELinux. I couldn't find it in the Debian spec (p
by craig_s_bell 2y ago
For some distributions, CIS benchmarks (also used by various other security tools) now include guidelines for SELinux.
I couldn't find it in the Debian spec (probably because it uses AppArmor), but the RHEL benchmark has these.
Currently, server level 1 only requires permissive mode:
https://www.tenable.com/audits/items/CIS_Red_Hat_Enterprise_Linux_9_v2.0.0_L1_Server.audit:647bbbfd028918a81c7a5281238e1361 https://www.tenable.com/audits/items/CIS_Red_Hat_Enterprise_...
CIS Red Hat Enterprise Linux 9 v2.0.0 L1 Server — 1.3.1.4 Ensure the SELinux mode is not disabled
... While server level 2 specifies enforcing mode:
https://www.tenable.com/audits/items/CIS_Red_Hat_Enterprise_Linux_9_v2.0.0_L2_Server.audit:acfe5d2a8c034a12a564619db0c03838 https://www.tenable.com/audits/items/CIS_Red_Hat_Enterprise_...
CIS Red Hat Enterprise Linux 9 v2.0.0 L2 Server — 1.3.1.5 Ensure the SELinux mode is enforcing