seusers(5) SELinux configuration seusers(5)NAME
seusers - The SELinux GNU/Linux user to SELinux user mapping configuration file
DESCRIPTION
The seusers file contains a list GNU/Linux user to SELinux user mapping for use by SELinux-aware login applications such as PAM(8).
selinux_usersconf_path(3) will return the active policy path to this file. The default SELinux users mapping file is located at:
/etc/selinux/{SELINUXTYPE}/seusers
Where {SELINUXTYPE} is the entry from the selinux configuration file config (see selinux_config(5)).
getseuserbyname(3) reads this file to map a GNU/Linux user or group to an SELinux user.
FILE FORMAT
Each line of the seusers configuration file consists of the following:
[%group_id]|[user_id]:seuser_id[:range]
Where:
group_id|user_id
The GNU/Linux user id, or if preceded by the percentage (%) symbol, then a GNU/Linux group id.
An optional entry set to __default__ can be provided as a fall back if required.
seuser_id
The SELinux user identity.
range
The optional level or range for an MLS/MCS policy.
EXAMPLE
# ./seusers
system_u:system_u:s0-s15:c0.c255
root:root:s0-s15:c0.c255
fred:user_u:s0
__default__:user_u:s0
%user_group:user_u:s0
SEE ALSO selinux(8), PAM(8), selinux_usersconf_path(3), getseuserbyname(3), selinux_config(5)Security Enhanced Linux 28-Nov-2011 seusers(5)
Check Out this Related Man Page
local.users(5) SELinux configuration local.users(5)NAME
local.users - The SELinux local users configuration file
DESCRIPTION
The file contains local user definitions in the form of policy language user statements and is only found on older SELinux systems as it
has been deprecated and replaced by the semange(8) services.
This file is only read by selinux_mkload_policy(3) when SETLOCALDEFS in the SELinux config file (see selinux_config(5)) is set to 1.
selinux_users_path(3) will return the active policy path to the directory where this file is located. The default local users file is:
/etc/selinux/{SELINUXTYPE}/contexts/users/local.users
Where {SELINUXTYPE} is the entry from the selinux configuration file config (see selinux_config(5)).
FILE FORMAT
The file consists of one or more entries terminated with ';', each on a separate line as follows:
user seuser_id roles role_id [[level level] [range range]];
Where:
user
The user keyword.
seuser_id
The SELinux user identifier.
roles
The roles keyword.
role_id
One or more previously declared role identifiers. Multiple role identifiers consist of a space separated list enclosed in
braces '{}'.
level
If MLS/MCS is configured, the level keyword.
level
The users default security level. Note that only the sensitivity component of the level (e.g. s0) is required.
range
If MLS/MCS is configured, the range keyword.
range
The current and clearance levels that the user can run. These are separated by a hyphen '-' as shown in the EXAMPLE section.
EXAMPLE
# ./users/local.users
user test_u roles staff_r level s0 range s0 - s15:c0.c1023;
SEE ALSO selinux(8), semanage(8), selinux_users_path(3), selinux_config(5), selinux_mkload_policy(3)Security Enhanced Linux 28-Nov-2011 local.users(5)
Hi,
Has anyone enabled SELinux on Amazon EC2?
I tried to enable SELinux using a CentOS image, and the steps in the following post, but it didn't work!!
Amazon Web Services Developer Community : Has anyone successfully enabled SELinux ...
The steps i took:
1)I started with CentOS 5.3 base... (5 Replies)
Everyone knows the project LFS (Linux from scratch), it is a book-assembly instructions GNU / Linux from source code. I managed to gather, then my knowledge of GNU / Linux grew, learned many new commands, edit config-files, base packages, kernel, etc. ..
Now I would like also to explore... (0 Replies)
I have an external drive (1 TB) attached via usb to a server running Red Hat Linux 6.2. During an application install one step requires perms set by root. Even though I could ls -l and see that root was able to do the 4755 but the install would fail. Someone pointed out the dot in the permission... (3 Replies)