PATH:
usr
/
lib
/
python3.9
/
site-packages
/
sepolicy
/
help
By Default on a SELinux Targeted Policy system, all users login using the unconfined_t user. But SELinux has a very powerful concept called confined users. You can setup individual users on your system to login with different SELinux user types. This Login Mapping Screen allows you to map a Linux login user to an SELinux User. Default SELinux Users: * Terminal user/ssh - guest_u - No Network, No setuid, no exec in homedir * Browser user/kiosk - xguest_u - Web access ports only. No setuid, no exec in homedir * Full Desktop user - User_u - Full Network, No SETUID. * Confined Admin/Desktop User - Staff_u - Full Network, sudo to admin only, no root password. Usually a confined admin * Unconfined user - unconfined_u (Default) - SELinux does not block access.
[-] lockdown_ptrace.png
[edit]
[-] transition_from.png
[edit]
[-] login_default.png
[edit]
[-] lockdown_ptrace.txt
[edit]
[-] lockdown_unconfined.txt
[edit]
[-] booleans_toggled.txt
[edit]
[-] transition_to.png
[edit]
[-] transition_from_boolean_2.txt
[edit]
[-] transition_from.txt
[edit]
[-] lockdown_permissive.txt
[edit]
[-] ports_outbound.txt
[edit]
[-] start.txt
[edit]
[-] files_write.png
[edit]
[-] booleans_toggled.png
[edit]
[-] start.png
[edit]
[-] transition_from_boolean.png
[edit]
[-] booleans_more_show.png
[edit]
[-] users.txt
[edit]
[-] users.png
[edit]
[-] system_current_mode.png
[edit]
[-] lockdown_permissive.png
[edit]
[-] file_equiv.png
[edit]
[-] system_boot_mode.png
[edit]
[-] __init__.py
[edit]
[-] system_relabel.png
[edit]
[-] booleans.txt
[edit]
[-] transition_file.png
[edit]
[-] ports_outbound.png
[edit]
[-] system.png
[edit]
[-] files_apps.txt
[edit]
[-] booleans.png
[edit]
[-] transition_file.txt
[edit]
[-] system_export.txt
[edit]
[-] booleans_more_show.txt
[edit]
[-] files_apps.png
[edit]
[-] files_exec.png
[edit]
[-] lockdown_unconfined.png
[edit]
[-] system_boot_mode.txt
[edit]
[-] files_write.txt
[edit]
[-] booleans_more.txt
[edit]
[+]
..
[-] transition_from_boolean_2.png
[edit]
[-] ports_inbound.png
[edit]
[-] transition_from_boolean_1.png
[edit]
[-] files_exec.txt
[edit]
[-] lockdown.png
[edit]
[-] file_equiv.txt
[edit]
[-] system_policy_type.png
[edit]
[-] booleans_more.png
[edit]
[-] lockdown.txt
[edit]
[-] system_policy_type.txt
[edit]
[-] transition_from_boolean_1.txt
[edit]
[-] system.txt
[edit]
[-] transition_from_boolean.txt
[edit]
[-] login_default.txt
[edit]
[-] ports_inbound.txt
[edit]
[+]
__pycache__
[-] system_relabel.txt
[edit]
[-] login.png
[edit]
[-] transition_to.txt
[edit]
[-] system_export.png
[edit]
[-] login.txt
[edit]
[-] system_current_mode.txt
[edit]