Documentation
yum install -y setools-console policycoreutils-python-utils
getenforce Disabled
sed -i 's/^SELINUX=.*$/SELINUX=permissive/g' /etc/selinux/config reboot
setsebool -P httpd_execmem on setsebool -P httpd_read_user_content on setsebool -P httpd_can_network_connect on setsebool -P httpd_can_network_connect_db on setsebool -P httpd_can_sendmail on setsebool -P httpd_unified on setsebool -P httpd_enable_homedirs onSELinux Semanage ALLOW port
semanage port -l | grep http_port_t semanage port -a -t http_port_t -p tcp 80 semanage port -a -t http_port_t -p tcp 8443 semanage port -a -t http_port_t -p tcp 443LPAR2RRD
chcon -R -t httpd_sys_rw_content_t /home/lpar2rrd/lpar2rrd chcon -R -t httpd_sys_content_t /home/lpar2rrd/lpar2rrd/www chcon -R -t httpd_sys_content_t /home/lpar2rrd/lpar2rrd/data chcon -R -t httpd_sys_script_exec_t /home/lpar2rrd/lpar2rrd/bin chcon -R -t httpd_sys_script_exec_t /home/lpar2rrd/lpar2rrd/load_*.sh chcon -R -t httpd_sys_script_exec_t /home/lpar2rrd/lpar2rrd/lpar2rrd-cgi chcon -R -t httpd_sys_script_exec_t /home/lpar2rrd/lpar2rrd/bin/vmware_install_image.shSTOR2RRD
chcon -R -t httpd_sys_rw_content_t /home/stor2rrd/stor2rrd chcon -R -t httpd_sys_script_exec_t /home/stor2rrd/stor2rrd/stor2rrd-cgi/ chcon -R -t httpd_sys_content_t /home/stor2rrd/stor2rrd/data/ chcon -R -t httpd_sys_content_t /home/stor2rrd/stor2rrd/www
setenforce 1 sed -i 's/^SELINUX=.*$/SELINUX=enforcing/g' /etc/selinux/config getenforce
tail -n 500 /var/log/audit/audit.log | grep -i avc grep "AVC" /var/log/audit/audit.log ausearch -m AVC,USER_AVC,SELINUX_ERR,USER_SELINUX_ERR -i ausearch -m AVC,USER_AVC,SELINUX_ERR,USER_SELINUX_ERR -ts recent