Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 1st November 2004, 02:26 AM
Linuxxx Offline
Registered User
 
Join Date: Feb 2004
Posts: 34
SELinux and Fedora

Hello

I'm just wondering why with my version of Fedora - 2.6.5-1.358 that when I type the command
$ id -Z
that I get this message

Sorry, --context ( -Z) can be used only on a selinux-enabled kernal.

If this is truly the case how do I enable SE in Fedora Core

Thank you
Scott
Reply With Quote
  #2  
Old 1st November 2004, 02:33 AM
tchung's Avatar
tchung Offline
FedoraNEWS.org Admin
 
Join Date: Feb 2004
Location: California, US
Posts: 561
This is from FC2 Release Notes: (http://fedoranews.org/tchung/fc2-fin...-NOTES-en.html)

Fedora Core 2 includes an implementation of SELinux. SELinux represents a major shift in the way users, programs, and processes interact. By default, SELinux is installed — but disabled — in this release.

Note:
You can install Fedora Core 2 with SELinux enabled by entering selinux at the Boot: prompt when booting the Fedora Core installation program.

Should you decide to enable SELinux, it is strongly recommended that you read the Fedora Core SELinux FAQ:

http://people.redhat.com/kwade/fedor...elinux-faq-en/

(UPDATE)
Q:. How do I install SELinux on a running Fedora Core 2 that didn't have SELinux installed through Anaconda?
A:. Since SELinux is now part of the kernel, installation is straightforward. You are enabling systems already in place.

1. Install a policy and the policy utilities with with yum install policy policycoreutils.
2. Create or edit /etc/sysconfig/selinux and set SELINUX=permissive in it. The file should have the standard permissions set with chmod 644 /etc/sysconfig/selinux.
3. Relabel your file system with fixfiles relabel. This will take at least several minutes, as each file on the system is checked and labeled for the newly installed policy.
4. Reboot your system. Check /var/log/messages for avc: denied messages. You may need to relabel the files again now that you are running fully under an SELinux policy domain. Resolve any issues while still in permissive mode, and once you can boot without avc denials, set SELINUX=enforcing in /etc/sysconfig/selinux.

Q:. How do I turn enforcing on/off at boot?
A:. You can specify the SELinux mode using the configuration file /etc/sysconfig/selinux.

# This is a comment field in /etc/sysconfig/selinux
#
# Allowable values are:
# enforcing - enables enforcing mode
# permissive - enables permissive mode
# disabled - disables SELinux
SELINUX=<value>

Setting the value to enforcing is the same as adding enforcing=1 to your command line when booting the kernel to turn enforcing on, while setting the value to permissive is the same as adding enforcing=0 to turn enforcing off. Note that the command line kernel parameter overrides the configuration file.

In the kernel that shipped with Fedora Core 2, setting the value to disabled was not the same as the selinux=0 kernel boot parameter. However, updated kernels act exactly the same if you disable in run time or at boot -- SELinux hooks and pseudo file system are unregistered entirely.

Thomas
__________________
Thomas Chung
http://fedoraproject.org/wiki/ThomasChung

Last edited by tchung; 1st November 2004 at 02:41 AM.
Reply With Quote
Reply

Tags
fedora, selinux

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Problem configuring SElinux using system-config-selinux GUI majdi Servers & Networking 0 6th September 2008 11:33 AM
selinux: hand tweaking policieand yum selinux-policy updates: overriden or perserved? mbiggerstaff Security and Privacy 1 19th December 2007 12:02 PM
Fedora 7, SELinux, and USB nulli_secundus Using Fedora 2 20th June 2007 10:01 AM
SELinux: Tons of errors with SELinux disabled Luis Security and Privacy 0 27th June 2005 11:05 PM
Test 3 w7o selinux installed, though lotsa selinux during usage? gafami Fedora Core 2 Test Releases 7 15th May 2004 08:15 AM


Current GMT-time: 03:12 (Wednesday, 19-06-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat