|
Packit Service |
9fb14c |
.TH "semanage" "8" "20100223" "" ""
|
|
Packit Service |
9fb14c |
.SH "NAME"
|
|
Packit Service |
9fb14c |
semanage \- SELinux Policy Management tool
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.SH "SYNOPSIS"
|
|
Packit Service |
9fb14c |
.B semanage {import,export,login,user,port,interface,module,node,fcontext,boolean,permissive,dontaudit,ibpkey,ibendport}
|
|
Packit Service |
9fb14c |
...
|
|
Packit Service |
9fb14c |
.B positional arguments:
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B import
|
|
Packit Service |
9fb14c |
Import local customizations
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B export
|
|
Packit Service |
9fb14c |
Output local customizations
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B login
|
|
Packit Service |
9fb14c |
Manage login mappings between linux users and SELinux confined users
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B user
|
|
Packit Service |
9fb14c |
Manage SELinux confined users (Roles and levels for an SELinux user)
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B port
|
|
Packit Service |
9fb14c |
Manage network port type definitions
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B interface
|
|
Packit Service |
9fb14c |
Manage network interface type definitions
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B module
|
|
Packit Service |
9fb14c |
Manage SELinux policy modules
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B node
|
|
Packit Service |
9fb14c |
Manage network node type definitions
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B fcontext
|
|
Packit Service |
9fb14c |
Manage file context mapping definitions
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B boolean
|
|
Packit Service |
9fb14c |
Manage booleans to selectively enable functionality
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B permissive
|
|
Packit Service |
9fb14c |
Manage process type enforcement mode
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B dontaudit
|
|
Packit Service |
9fb14c |
Disable/Enable dontaudit rules in policy
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B ibpkey
|
|
Packit Service |
9fb14c |
Manage infiniband pkey type definitions
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.B ibendport
|
|
Packit Service |
9fb14c |
Manage infiniband end port type definitions
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.SH "DESCRIPTION"
|
|
Packit Service |
9fb14c |
semanage is used to configure certain elements of
|
|
Packit Service |
9fb14c |
SELinux policy without requiring modification to or recompilation
|
|
Packit Service |
9fb14c |
from policy sources. This includes the mapping from Linux usernames
|
|
Packit Service |
9fb14c |
to SELinux user identities (which controls the initial security context
|
|
Packit Service |
9fb14c |
assigned to Linux users when they login and bounds their authorized role set)
|
|
Packit Service |
9fb14c |
as well as security context mappings for various kinds of objects, such
|
|
Packit Service |
9fb14c |
as network ports, interfaces, infiniband pkeys and endports, and nodes (hosts)
|
|
Packit Service |
9fb14c |
as well as the file context mapping. Note that the semanage login command deals
|
|
Packit Service |
9fb14c |
with the mapping from Linux usernames (logins) to SELinux user identities,
|
|
Packit Service |
9fb14c |
while the semanage user command deals with the mapping from SELinux
|
|
Packit Service |
9fb14c |
user identities to authorized role sets. In most cases, only the
|
|
Packit Service |
9fb14c |
former mapping needs to be adjusted by the administrator; the latter
|
|
Packit Service |
9fb14c |
is principally defined by the base policy and usually does not require
|
|
Packit Service |
9fb14c |
modification.
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.SH "OPTIONS"
|
|
Packit Service |
9fb14c |
.TP
|
|
Packit Service |
9fb14c |
.I \-h, \-\-help
|
|
Packit Service |
9fb14c |
List help information
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.SH "SEE ALSO"
|
|
Packit Service |
9fb14c |
.BR selinux (8),
|
|
Packit Service |
9fb14c |
.BR semanage-boolean (8),
|
|
Packit Service |
9fb14c |
.BR semanage-dontaudit (8),
|
|
Packit Service |
9fb14c |
.BR semanage-export (8),
|
|
Packit Service |
9fb14c |
.BR semanage-fcontext (8),
|
|
Packit Service |
9fb14c |
.BR semanage-import (8),
|
|
Packit Service |
9fb14c |
.BR semanage-interface (8),
|
|
Packit Service |
9fb14c |
.BR semanage-login (8),
|
|
Packit Service |
9fb14c |
.BR semanage-module (8),
|
|
Packit Service |
9fb14c |
.BR semanage-node (8),
|
|
Packit Service |
9fb14c |
.BR semanage-permissive (8),
|
|
Packit Service |
9fb14c |
.BR semanage-port (8),
|
|
Packit Service |
9fb14c |
.BR semanage-user (8)
|
|
Packit Service |
9fb14c |
.BR semanage-ibkey (8),
|
|
Packit Service |
9fb14c |
.BR semanage-ibendport (8),
|
|
Packit Service |
9fb14c |
|
|
Packit Service |
9fb14c |
.SH "AUTHOR"
|
|
Packit Service |
9fb14c |
This man page was written by Daniel Walsh <dwalsh@redhat.com>
|
|
Packit Service |
9fb14c |
.br
|
|
Packit Service |
9fb14c |
and Russell Coker <rcoker@redhat.com>.
|
|
Packit Service |
9fb14c |
.br
|
|
Packit Service |
9fb14c |
Examples by Thomas Bleher <ThomasBleher@gmx.de>.
|
|
Packit Service |
9fb14c |
usage: semanage [\-h]
|