Routine SELinux System Use and Administration
SELinux is largely transparent to ordinary system users and presents system administrators with few complications. This section describes the handful of issues that users and administrators need to be aware of when using and administering an SELinux system. The issues fall into the following broad categories:
Entering a role
Viewing security contexts
Adding users and groups
Starting and controlling daemons
Tuning SELinux
Entering a Role
Recall
that,
as explained in Chapter 2, SELinux users have
one or more associated roles and, at any time, are bound to exactly
one of these. Users are initially bound to a role at login time.
Thereafter, a user can issue a special command to replace this
binding with a binding to any role for which the user is authorized.
System administrators may use this command to transition back and
forth between the staff_r and
sysadm_r roles. Otherwise, role transitions are
relatively rare.
The standard SELinux security policy defines four roles:
-
staff_r Used for users permitted to enter the
sysadm_rrole-
sysadm_r Used for the system administrator
-
system_r Used for system processes and objects
-
user_r Used for ordinary users
Tip
The flexibility of SELinux makes it possible for SELinux administrators to define additional roles. However, few administrators find any need to do so. The four canonical roles are the only roles found on most SELinux systems.
When a user logs into an SELinux system, the system will either:
Automatically ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access