SELinux building module: Difference between revisions

From Integrics Wiki
Jump to navigation Jump to search
Content deleted Content added
Created page with "To check for SELinux audit entries: <pre> audit2allow -a -b </pre> To turn SELinux audit entries into a new SELinux module: <pre> audit2allow -a -b -M enswitch </pre> To com..."
 
No edit summary
 
(One intermediate revision by one other user not shown)
Line 16: Line 16:
semodule -i enswitch.pp
semodule -i enswitch.pp
rm enswitch.mod
rm enswitch.mod
</pre>

To check the SELinux module for Enswitch is installed:
<pre>
semodule -l | grep enswitch
</pre>

To remove the installed SELinux module for Enswitch:
<pre>
semodule -r enswitch
</pre>

To list the contents of the .pp file:
<pre>
/usr/libexec/selinux/hll/pp /opt/enswitch/etc/selinux/enswitch.pp
</pre>
</pre>

Latest revision as of 04:29, 29 August 2025

To check for SELinux audit entries:

audit2allow -a -b

To turn SELinux audit entries into a new SELinux module:

audit2allow -a -b -M enswitch

To compile the SELinux module for Enswitch:

cd /opt/enswitch/current/etc/selinux
checkmodule -M -m -o enswitch.mod enswitch.te
semodule_package -o enswitch.pp -m enswitch.mod
semodule -i enswitch.pp
rm enswitch.mod

To check the SELinux module for Enswitch is installed:

semodule -l | grep enswitch

To remove the installed SELinux module for Enswitch:

semodule -r enswitch

To list the contents of the .pp file:

/usr/libexec/selinux/hll/pp /opt/enswitch/etc/selinux/enswitch.pp