What is SELinux? | SELinux Commands

preview_player
Показать описание
This video answers the questions what is SELinux and explains the various SELinux commands you should know. It breaks down the 3 modes of SELinux.
1. Enforcing
2. Permissive
3. Disabled
I also go into why people change SELinux modes and which distribution have SELinux Enforcing by default. SELinux basically breaks down all processes into labels and assigns them independent privileges based on the SELinux label.

Commands:
Check SELinux status
# sestatus OR # getenforce

Temporarily enforce SELinux
# setenforce 1

Permanently change SELinux
# nano /etc/selinux/config
---CHANGE--- SELinux=disabled

Check if it is blocking anything
# ausearch -m AVC,USER_AVC -ts recent

Keeping SELinux enforcing or permissive
Many companies do not take the time to make their application SELinux compatible and if you leave it enabled you will probably need to do ome additional troubleshooting with the "setroubleshoot" command.

Рекомендации по теме
Комментарии
Автор

But you did not explain what SELinux is ?

wqgwlgf
Автор

Thank you, very informative. I need to learn some SELINUX and this was straight to the point and was short enough to not feel overwhelmed.

Innovationlu
Автор

Dear Sir, to set the SELinux status to Enforce or Permissive, the command <setenforce> can be used... to check the status <getenforce>

jpberes
Автор

Hi Chris!
What distribution and DE you use in this video?

plumflorin
Автор

I didnt get the answer for "what is se linux?" from this, this video was more how to check if its enabled. I know that's its security enhanced but what does that mean?

AronW
Автор

Thank you. Great explanation and speech speed for a foreign ear.

bama
Автор

your eye and t.shirt color is same. lol

randomtopics
Автор

Old but gold, SELinux was messing with my STEAM games on Flatpak, this made it clear why.

chucklebeats
Автор

I had a hell of a time just trying to get the grub to update. This should be fun (actually pain).

brendananderson
Автор

SELinux is just Fedora's alternative to Ubuntu's AppArmor? In other words, it's a security feature that limits what apps can run and do, similar to how you have to give apps explicit permission to do certain things on an Android phone, except it focuses on the apps as a whole instead of individual access features. Is that an accurate summary?

majoraslayer
Автор

hi Chris
I think I will really need your help...
I want to flash custom ROM in my redmi 7. but I can't because I'm unable to access some system files which located in the storage. I can't wipe then because their use superblock backups. please can you help me, I really need to wipe all the storage file. help me please

attesores
Автор

idol can you make a video more about Permissive vs Enforcing because I heard Permissive has backdoor business esp android custom rom. thanks

lowcosttech
Автор

Can you do the same video for AppArmor? I use Ubuntu on the server and that comes with AppArmor by default. I never needed to mess with it but some basic managing video-info would be nice.

michadybczak
Автор

Currently, I am testing SELinux on an Ubuntu 22.04.4 virtual machine & when I enable enforcing, mode the network gets turned off. Funny enough, when I enabled permissive mode, the network is restored. Am I configuring it wrong?

MichaelBullutKE
Автор

Hi Chris, how to do it in Debian 12 2024 ?

ultraprimez
Автор

Sir can u pls give me a clear discription whether its safe or not or how ro remove or use it with mobiles ...while checking whether my mob got rooted i found selunix enforced and also found that a root was inactive and through spath system/etc/bin/toy

sandeepkumarsurada
Автор

I think nod32 is better than SELinux !

aniksen
Автор

This video shouldn't be taken seriously. Disabling SELinux or setting it to Permissive is against distro and industry standards.
Instead, please research on how to e.g. allow your binary to do execheap or similar, but only on the binary you need to run.

toquitad
Автор

This video is not even close for a minimal explanation either. This is only what you could understand about SELinux which is zero. Waste of time.

csodarudi
Автор

play it at least 1.25x t get rid of the lazy voice

jessicalewisjessielew