semanage.md 1.5 KB

semanage

SELinux ์˜๊ตฌ ์ •์ฑ… ๊ด€๋ฆฌ ๋„๊ตฌ. boolean, fcontext, port ๋“ฑ์˜ ์ผ๋ถ€ ํ•˜์œ„ ๋ช…๋ น์—๋Š” ์ž์ฒด ์‚ฌ์šฉ ์„ค๋ช…์„œ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ๋” ๋งŽ์€ ์ •๋ณด: https://manned.org/semanage.

  • SELinux ๋ถˆ๋ฆฌ์–ธ ์„ค์ • ๋˜๋Š” ํ•ด์ œ. ๋ถˆ๋ฆฌ์–ธ์€ ๊ด€๋ฆฌ์ž๊ฐ€ ์ •์ฑ… ๊ทœ์น™์ด ์ œํ•œ๋œ ํ”„๋กœ์„ธ์Šค ์œ ํ˜•(๋„๋ฉ”์ธ)์— ์–ด๋–ป๊ฒŒ ์˜ํ–ฅ์„ ๋ฏธ์น˜๋Š”์ง€ ์‚ฌ์šฉ์ž ์ •์˜ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•จ:

sudo semanage boolean {{-m|--modify}} {{-1|--on|-0|--off}} {{haproxy_connect_any}}

  • ์‚ฌ์šฉ์ž ์ •์˜ ํŒŒ์ผ ์ปจํ…์ŠคํŠธ ๋ ˆ์ด๋ธ”๋ง ๊ทœ์น™ ์ถ”๊ฐ€. ํŒŒ์ผ ์ปจํ…์ŠคํŠธ๋Š” ์ œํ•œ๋œ ๋„๋ฉ”์ธ์ด ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋Š” ํŒŒ์ผ์„ ์ •์˜ํ•จ:

sudo semanage fcontext {{-a|--add}} {{-t|--type}} {{samba_share_t}} '/mnt/share(/.*)?'

  • ์‚ฌ์šฉ์ž ์ •์˜ ํฌํŠธ ๋ ˆ์ด๋ธ”๋ง ๊ทœ์น™ ์ถ”๊ฐ€. ํฌํŠธ ๋ ˆ์ด๋ธ”์€ ์ œํ•œ๋œ ๋„๋ฉ”์ธ์ด ์ฒญ์ทจํ•  ์ˆ˜ ์žˆ๋Š” ํฌํŠธ๋ฅผ ์ •์˜ํ•จ:

sudo semanage port {{-a|--add}} {{-t|--type}} {{ssh_port_t}} {{-p|--proto}} {{tcp}} {{22000}}

  • ์ œํ•œ๋œ ๋„๋ฉ”์ธ์— ๋Œ€ํ•œ ํ—ˆ์šฉ ๋ชจ๋“œ ์„ค์ • ๋˜๋Š” ํ•ด์ œ. ๋„๋ฉ”์ธ๋ณ„ ํ—ˆ์šฉ ๋ชจ๋“œ๋Š” setenforce์— ๋น„ํ•ด ๋” ์„ธ๋ถ„ํ™”๋œ ์ œ์–ด๋ฅผ ์ œ๊ณตํ•จ:

sudo semanage permissive {{-a|--add|-d|--delete}} {{httpd_t}}

  • ๊ธฐ๋ณธ ์ €์žฅ์†Œ์—์„œ ๋กœ์ปฌ ์‚ฌ์šฉ์ž ์ •์˜ ์ถœ๋ ฅ:

sudo semanage export {{-f|--output_file}} {{๊ฒฝ๋กœ/๋Œ€์ƒ/ํŒŒ์ผ}}

  • semanage export๋กœ ์ƒ์„ฑ๋œ ํŒŒ์ผ์„ ๋กœ์ปฌ ์‚ฌ์šฉ์ž ์ •์˜์— ๊ฐ€์ ธ์˜ค๊ธฐ (์ฃผ์˜: ํ˜„์žฌ ์‚ฌ์šฉ์ž ์ •์˜๊ฐ€ ์ œ๊ฑฐ๋  ์ˆ˜ ์žˆ์Œ!):

sudo semanage import {{-f|--input_file}} {{๊ฒฝ๋กœ/๋Œ€์ƒ/ํŒŒ์ผ}}