LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-08-2012, 12:38 PM   #1
dcarrington
Member
 
Registered: Dec 2011
Distribution: RHEL, CentOS, Ubuntu
Posts: 61

Rep: Reputation: 2
SELinux still disabled


Hello,

While reviewing some of my servers, I noticed that a few of them had SELinux disabled. It is my understanding that I should be able to run 'setenforce 1' or 'setenforce 0' to put SELinux in enforcing or permissive mode without requiring a restart.

However, when I run 'setenforce 0' I get the message 'setenforce: SELinux is disabled'

I have modified the /etc/selinux/config file so that it restarts in permissive mode, but I am trying to avoid a reboot as this particular server has a very narrow maintenance window and I have to jump through a lot of hoops if I want to reboot it without getting into a lot of trouble.

Has anyone seen this before? Am I just missing something?

Thanks!!
 
Old 03-08-2012, 12:52 PM   #2
T3RM1NVT0R
Senior Member
 
Registered: Dec 2010
Location: Internet
Distribution: Linux Mint, SLES, CentOS, Red Hat
Posts: 2,385

Rep: Reputation: 477Reputation: 477Reputation: 477Reputation: 477Reputation: 477
@ Reply

Hi dcarrington,

It will not work without a reboot because when you enable selinux it relabels the file system. As you said that you have already edited /etc/selinux/config to enable selinux and run in permissive mode but the changes will take place only after reboot.
 
1 members found this post helpful.
Old 03-08-2012, 03:42 PM   #3
dcarrington
Member
 
Registered: Dec 2011
Distribution: RHEL, CentOS, Ubuntu
Posts: 61

Original Poster
Rep: Reputation: 2
Well, that is unfortunate. I was really hoping to avoid a reboot, but there may just be no way around it.

Thanks!!
 
Old 03-09-2012, 07:24 AM   #4
T3RM1NVT0R
Senior Member
 
Registered: Dec 2010
Location: Internet
Distribution: Linux Mint, SLES, CentOS, Red Hat
Posts: 2,385

Rep: Reputation: 477Reputation: 477Reputation: 477Reputation: 477Reputation: 477
@ Reply

Well that is how it works when it comes to selinux. As selinux changes the context for files and directories on reboot basically relabelling. This also applies if you change selinux from permissive to targeted mode.

Please mark the thread as solved if you think your query has been answered.

Enjoy linux!!!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Boot hangs after SELinux: Disabled at runtime DaveJL Linux - Software 6 06-23-2014 06:56 AM
SELinux disabled and Redhat? johndev Linux - Newbie 5 05-19-2011 01:55 PM
ubuntu server SELinux is disabled ganesh24pal@gmail.com Linux - Server 1 11-18-2010 06:00 AM
How can I disabled SELinux? abefroman Linux - Kernel 3 09-17-2006 10:22 AM
getsebool: SELinux is disabled ?? dansawyer Linux - Security 4 09-14-2006 03:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:24 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration