SV-261370r996551_rule
V-261370
SRG-OS-000445-GPOS-00199
SLEM-05-431020
CAT II
10
Configure SLEM 5 to verify correct operation of all security functions.
Add or modify the following line in the "/etc/selinux/config" file:
SELINUXTYPE=targeted
A reboot is required for the changes to take effect.
Verify "SELinux" is active and enforcing the targeted policy with the following command:
> sudo sestatus
SELinux status: enabled
SELinuxfs mount: /sys/fs/selinux
SELinux root directory: /etc/selinux
Loaded policy name: targeted
Current mode: enforcing
Mode from config file: enforcing
Policy MLS status: enabled
Policy deny_unknown status: allowed
Memory protection checking: actual (secure)
Max kernel policy version: 33
If the "Loaded policy name" is not set to "targeted", this is a finding.
V-261370
False
SLEM-05-431020
Verify "SELinux" is active and enforcing the targeted policy with the following command:
> sudo sestatus
SELinux status: enabled
SELinuxfs mount: /sys/fs/selinux
SELinux root directory: /etc/selinux
Loaded policy name: targeted
Current mode: enforcing
Mode from config file: enforcing
Policy MLS status: enabled
Policy deny_unknown status: allowed
Memory protection checking: actual (secure)
Max kernel policy version: 33
If the "Loaded policy name" is not set to "targeted", this is a finding.
M
5596