SELinux Part1

Sdílet
Vložit
  • čas přidán 28. 08. 2024
  • Playlist:
    • SELinux Concepts and E...
    This is a module from a complete training coming up.

Komentáře • 7

  • @natarajsathish-mp4nw
    @natarajsathish-mp4nw Před měsícem +1

    Brilliant and crisp explanation ,this one stands out from other Selinux tutorials. Thank you.

  • @JDSalinger8258
    @JDSalinger8258 Před 11 měsíci +3

    Exceptionally well done. Sets a high bar for other Linux videos

  • @Supermario-kx9fj
    @Supermario-kx9fj Před 9 měsíci +1

    Perfect and clear

  • @HaukeLaging
    @HaukeLaging Před 5 měsíci +1

    The first example (preventing httpd from accessing passwd) is not great because that problem does not require an LSM (except for the initial httpd process which is running as UID 0). You could fix that with a new group and adding all the (dis)allowed users to it; either with the main group or an ACL group.

    • @uadmin
      @uadmin  Před 5 měsíci

      Thanks for your comment! 👍

    • @jirehla-ab1671
      @jirehla-ab1671 Před 4 měsíci

      ​@@uadminif i run multiple database instances in same machine, Would that be considered multi tenant system? And how would selinux handle it?

    • @uadmin
      @uadmin  Před 4 měsíci

      @@jirehla-ab1671 I a not sure, but maybe you should look at fcontexts. semanage fcontext -a -t dirsrv_var_lib_t /srv/dirsrv/instance_name/db/
      restorecon -Rv /srv/dirsrv/instance_name/db/