Yadda Ake Kashe SELinux Na Wani Lokaci Ko Kuma Dindindin


Ana ɗaukar Linux a matsayin ɗayan ingantattun tsarukan aiki da zaku iya amfani dasu a yau, wannan saboda kyawawan ayyukan aiwatar da tsaro kamar su SELinux (Tsaro-Ingantaccen Linux).

Don masu farawa, ana bayyana SELinux a matsayin tsarin tsaro mai izini na dole (MAC) wanda aka aiwatar a cikin kwaya. SELinux yana ba da hanyar aiwatar da wasu manufofin tsaro wanda in ba haka ba mai Gudanar da Tsarin ba zai aiwatar da shi ba.

Lokacin da kake shigar da RHEL/CentOS ko wasu ƙididdiga masu yawa, ana amfani da fasalin SELinux ko sabis ta tsohuwa, saboda wannan wasu aikace-aikacen da ke kan tsarinku na ainihi ba za su iya tallafawa wannan hanyar tsaro ba. Sabili da haka, don yin waɗannan aikace-aikacen suna aiki kullum, dole ne ku kashe ko kashe SELinux.

Mahimmi: Idan ba ku so ku kashe SELinux, to ya kamata ku karanta waɗannan labaran don aiwatar da wasu ikon isa ga tilas akan fayiloli da sabis don suyi aiki daidai.

A wannan hanyar yadda za'a jagoranta, zamu bi ta matakan da zaku iya bi don bincika matsayin SELinux sannan kuma musaki SELinux a cikin CentOS/RHEL da Fedora, idan an sami damar.

Ta Yaya Zan Kashe SELinux a cikin Linux

Abu na farko da zaka yi shine bincika matsayin SELinux akan tsarin ka, kuma zaka iya yin hakan ta hanyar bin umarnin nan mai zuwa:

$ sestatus

Gaba, ci gaba da nakasa SELinux a kan tsarinku, ana iya yin hakan na ɗan lokaci ko na dindindin gwargwadon abin da kuke son cimmawa.

Don kashe SELinux na ɗan lokaci, ba da umarnin da ke ƙasa azaman tushe:

# echo 0 > /selinux/enforce

A madadin, zaku iya amfani da kayan aiki setenforce kamar haka:

# setenforce 0

Wani, yi amfani da zaɓin Izini maimakon 0 kamar yadda yake a ƙasa:

# setenforce Permissive

Wadannan hanyoyin da ke sama zasuyi aiki ne kawai har zuwa sake yi na gaba, sabili da haka don kashe SELinux har abada, matsa zuwa sashe na gaba.

Don kashe SELinux har abada, yi amfani da editan da kuka fi so don buɗe fayil ɗin /etc/sysconfig/selinux kamar haka:

# vi /etc/sysconfig/selinux

Sannan canza umarnin SELinux = tilastawa zuwa SELinux = an kashe kamar yadda aka nuna a hoton da ke ƙasa.

SELINUX=disabled

Bayan haka, adana da fita fayil ɗin, don canje-canje su fara aiki, kuna buƙatar sake kunna tsarin ku sannan ku duba matsayin SELinux ta amfani da umarnin sestatus kamar yadda aka nuna:

$ sestatus

A ƙarshe, mun ci gaba ta hanyoyi masu sauƙi da zaku iya bi don musaki SELinux akan CentOS/RHEL da Fedora. Babu wani abu da yawa da za'a rufe a ƙarƙashin wannan batun amma ƙari, samun ƙarin game da SELinux na iya tabbatar da taimako musamman ga waɗanda ke da sha'awar bincika fasalin tsaro a cikin Linux.