LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 06-13-2013, 05:56 PM   #1
forrie
Member
 
Registered: Sep 2003
Distribution: RedHat
Posts: 41

Rep: Reputation: 15
SELinux context showing up even when disabled


I have SELinux disabled, the system has been rebooted -- yet, the ls -l output is clearly showing the "." at the end of the permissions which indicates a context still present.

How can I disable this system-wide - moreso, I wonder why it's happening. These systems were just built and I have 2 which I installed pretty much identically.


thanks.
 
Old 06-13-2013, 07:01 PM   #2
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
Labels on files don't just go away when SELinux is disabled, it is just that the checks aren't made using them.

Why do you need it disabled?
 
Old 06-13-2013, 07:38 PM   #3
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,359

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
This++
Quote:
Why do you need it disabled?
 
Old 06-14-2013, 10:25 AM   #4
forrie
Member
 
Registered: Sep 2003
Distribution: RedHat
Posts: 41

Original Poster
Rep: Reputation: 15
We have some systems that need SELinux disabled to run. Don't ask me way, I don't write code.

In any case, I installed two identical systems of CentOS 6.4. One system shows the dots a the end of the LS output, the other does not. Both have SElinux disabled. That's very bizarre.
 
Old 06-14-2013, 01:57 PM   #5
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
Not really. If the install restorecon did not run, then the labels will not be applied.
 
Old 06-17-2013, 06:20 AM   #6
pix9
Member
 
Registered: Jan 2010
Location: Mumbai, India
Distribution: ArchLinux, Fedora 24, Centos 7.0
Posts: 177

Rep: Reputation: 19
Smile

SeLinux is a security framework which works over, normal permissions, they have defined a policy which contains information about who can access what, when SELinux is in enforcing mode, it will check and control, access to resources. This is accomplished by meanse of security context, like in our normal permissions we have "read" "write" and "execute", in same manner selinux have diffrent type of security context labled on all the files, if selinux is in enforcing mode these context will be checked and access will be allowed accordingly. But if selinux is disabled security context will not be checked, thus SELinux will not interfear in your access when it is disabled even if it shows security context files and folders.

regards

Last edited by pix9; 06-17-2013 at 06:24 AM.
 
Old 06-17-2013, 09:01 AM   #7
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
And you really ought to find out why you have to run systems with low security.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SELinux change context to my own name kingkashif Programming 1 03-16-2013 07:44 AM
[SOLVED] SELinux - Best Context to Use dcarrington Linux - Server 7 07-11-2012 04:25 PM
[SOLVED] SElinux context for FTP smilemukul Linux - Newbie 3 09-23-2010 05:35 PM
SElinux context problem Bit-Devil Linux - Security 0 12-04-2009 06:58 PM
invalid context in SELinux lothario Linux - Security 1 06-17-2005 04:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:10 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration