{"id":694,"date":"2006-06-04T19:42:11","date_gmt":"2006-06-04T19:42:11","guid":{"rendered":"http:\/\/ellery.no-ip.info\/wp\/thinkingmore\/2006\/06\/04\/selinux-tip\/"},"modified":"2006-06-04T19:42:11","modified_gmt":"2006-06-04T19:42:11","slug":"selinux-tip","status":"publish","type":"post","link":"https:\/\/ellery.no-ip.info\/wp\/thinkingmore\/2006\/06\/selinux-tip\/","title":{"rendered":"SELinux tip"},"content":{"rendered":"<p>\u4eca\u5929\u8981\u7528\u5230\u6642\uff0c\u624d\u9a5a\u89ba\u4ee5\u524d\u7684\u7b46\u8a18\u5c45\u7136\u4e0d\u898b\u4e86&#8230;\uff0c\u52aa\u529b\u56de\u60f3\u4e86\u597d\u4e00\u9663\u5b50\uff0c\u624d\u60f3\u8d77\u4f86\u3002<br \/>\n\u4e00\u822c\u4f86\u8aaa\uff0c\u5982\u679c\u4e0d\u719f\u7684\u8a71\uff0c\u6700\u597d\u662f\u95dc\u6389 SELinux \u9078\u9805\u3002<br \/>\n\u90a3\u6211\u70ba\u751a\u9ebc\u8981\u7528\uff1f&#8230;..\u5225\u554f\u4e86\u5427&#8230;.<br \/>\nSELinux \u7684 policy \u771f\u7684\u662f\u8907\u96dc\uff0c\u8907\u96dc\u5230\u6211\u5be6\u5728\u662f\u4e0d\u592a\u60f3\u770b\u4e0b\u53bb\u3002<br \/>\n\u9019\u88e1\u6709\u500b\u7c21\u55ae\u7684\u65b9\u6cd5\u53ef\u4ee5\u5e6b\u4f60\u7522\u751f policy\uff0c\u9996\u5148\uff0c\u5148\u53bb\u57f7\u884c\u88ab SELinux \u963b\u64cb\u7684\u7a0b\u5f0f\uff0c\u7136\u5f8c\u57f7\u884c<br \/>\n#audit2allow -d -o xxx.policy<br \/>\n\u9019\u6703\u7522\u751f xxx.policy<br \/>\n\u63a5\u8457\u628a\u9019\u500b\u6a94\u6848\u8907\u88fd\u5230 \/etc\/selinux\/targeted\/src\/policy\/domains\/misc\/local.te<br \/>\n\u5207\u5230 \/etc\/selinux\/targeted\/src\/policy\/<br \/>\n\u57f7\u884c make reload<br \/>\n\u9019\u6a23\u5c31\u5927\u529f\u544a\u6210\u4e86\u3002<br \/>\np.s. \u6211\u7684\u74b0\u5883\u662fCentOS 4.3\uff0cRHEL\u3001WHEL\u3001Fedora\u61c9\u8a72\u90fd\u5dee\u4e0d\u591a\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4eca\u5929\u8981\u7528\u5230\u6642\uff0c\u624d\u9a5a\u89ba\u4ee5\u524d\u7684\u7b46\u8a18\u5c45\u7136\u4e0d\u898b\u4e86&#8230;\uff0c\u52aa\u529b\u56de\u60f3\u4e86\u597d\u4e00\u9663\u5b50\uff0c\u624d\u60f3\u8d77\u4f86\u3002 \u4e00\u822c\u4f86\u8aaa\uff0c\u5982\u679c\u4e0d\u719f\u7684\u8a71\uff0c\u6700\u597d\u662f\u95dc\u6389 SELinux \u9078\u9805\u3002 \u90a3\u6211\u70ba\u751a\u9ebc\u8981\u7528\uff1f&#8230;..\u5225\u554f\u4e86\u5427&#8230;. SELinux \u7684 policy \u771f\u7684\u662f\u8907\u96dc\uff0c\u8907\u96dc\u5230\u6211\u5be6\u5728\u662f\u4e0d\u592a\u60f3\u770b\u4e0b\u53bb\u3002 \u9019\u88e1\u6709\u500b\u7c21\u55ae\u7684\u65b9\u6cd5\u53ef\u4ee5\u5e6b\u4f60\u7522\u751f policy\uff0c\u9996\u5148\uff0c\u5148\u53bb\u57f7\u884c\u88ab SELinux \u963b\u64cb\u7684\u7a0b\u5f0f\uff0c\u7136\u5f8c\u57f7\u884c #audit2allow -d -o xxx.policy \u9019\u6703\u7522\u751f xxx.policy \u63a5\u8457\u628a\u9019\u500b\u6a94\u6848\u8907\u88fd\u5230 \/etc\/selinux\/targeted\/src\/policy\/domains\/misc\/local.te \u5207\u5230 \/etc\/selinux\/targeted\/src\/policy\/ \u57f7\u884c make reload \u9019\u6a23\u5c31\u5927\u529f\u544a\u6210\u4e86\u3002 p.s. \u6211\u7684\u74b0\u5883\u662fCentOS 4.3\uff0cRHEL\u3001WHEL\u3001Fedora\u61c9\u8a72\u90fd\u5dee\u4e0d\u591a\u3002<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[8],"tags":[],"class_list":["post-694","post","type-post","status-publish","format-standard","hentry","category-linux-"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p2MOxp-bc","_links":{"self":[{"href":"https:\/\/ellery.no-ip.info\/wp\/thinkingmore\/wp-json\/wp\/v2\/posts\/694","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ellery.no-ip.info\/wp\/thinkingmore\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ellery.no-ip.info\/wp\/thinkingmore\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ellery.no-ip.info\/wp\/thinkingmore\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ellery.no-ip.info\/wp\/thinkingmore\/wp-json\/wp\/v2\/comments?post=694"}],"version-history":[{"count":0,"href":"https:\/\/ellery.no-ip.info\/wp\/thinkingmore\/wp-json\/wp\/v2\/posts\/694\/revisions"}],"wp:attachment":[{"href":"https:\/\/ellery.no-ip.info\/wp\/thinkingmore\/wp-json\/wp\/v2\/media?parent=694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ellery.no-ip.info\/wp\/thinkingmore\/wp-json\/wp\/v2\/categories?post=694"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ellery.no-ip.info\/wp\/thinkingmore\/wp-json\/wp\/v2\/tags?post=694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}