
ããã«ã¡ã¯ååïŒ
ç§ãã¡ã®å€ãã¯ãWebãããžã§ã¯ãã®éçšãµãŒããŒã®ã»ããã¢ããã«é¢äžããŠããŸãã ApacheãNginxã®æ§ææ¹æ³ã«ã€ããŠã¯èª¬æããŸãããããã«ã€ããŠã¯ãç§ãããããç¥ã£ãŠããŸãã ãã ããããã³ããšã³ããµãŒããŒãäœæããéã®éèŠãªåŽé¢ã®1ã€ã¯æ¶ç¯ããŠããŸãããããã¯ã»ãã¥ãªãã£ãµãã·ã¹ãã ã®èšå®ã§ãã
ãDisable SELinuxãã¯ãã»ãšãã©ã®ã¢ããã¥ã¢ã¬ã€ãã®æšæºçãªæšå¥šäºé
ã§ãã ãœããããªã·ãŒã¢ãŒãã§ã»ãã¥ãªãã£ãµãã·ã¹ãã ãèšå®ããããã»ã¹ã¯ãã»ãšãã©ã®å Žåéåžžã«ç°¡åãªã®ã§ãããã¯æ¥ãã§æ±ºå®ããããã«æããŸãã
仿¥ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®Red HatïŒCentOSïŒãã¡ããªã§äœ¿çšãããSELinuxã»ãã¥ãªãã£ãµãã·ã¹ãã ã調æŽããããã€ãã®æ¹æ³ã«ã€ããŠèª¬æããŸãã äŸãšããŠãCentOSããŒãžã§ã³5.8ã§Apache +
mod_wsgi +
Django +
ZEO WebãµãŒããŒã®ãã³ãã«ãæ§æããŸãã
Linuxã»ãã¥ãªãã£ã·ã¹ãã ãæ§æããå Žåãéæã¢ã¯ã»ã¹å¶åŸ¡ïŒDACïŒã·ã¹ãã ã®ãã¬ãŒã ã¯ãŒã¯ã«å¶çŽãããŸãã 3ã€ã®ã¬ãã«ïŒææè
ãã°ã«ãŒãææè
ãªã©ïŒããã³POSIX ACLã®rwxã®æšæºæš©éãèªç±ã«äœ¿çšã§ããŸãã ãããã£ãŠããŠãŒã¶ãŒæš©éãæã€ã¢ããªã±ãŒã·ã§ã³ã¯ãçè«çã«ã¯ã察å¿ãããŠãŒã¶ãŒãå©çšã§ãããã¹ãŠã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã ã¢ããªã±ãŒã·ã§ã³ãå±éºã«ããããããšãæ²ããçµæãæãå¯èœæ§ããããŸãã
SELinuxïŒSecurity-Enhanced LinuxïŒã¯ãMandatory Access ControlïŒMACïŒãå®è£
ããã»ãã¥ãªãã£ãµãã·ã¹ãã ã§ãããåŸæ¥ã®è£éã·ã¹ãã ãšäžŠè¡ããŠåäœããŸãã ã¢ã¯ã»ã¹æš©ã¯ãããªã·ãŒã䜿çšããŠã·ã¹ãã ã«ãã£ãŠæ±ºå®ãããŸãã ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®Red HatïŒCentOSïŒãã¡ããªã§ã¯ãã«ãŒãã«ã®äžéšãšããŠããã«SELinuxãå
¥æã§ããŸãã ã¿ã¹ã¯ã®æãç°¡åãªãœãªã¥ãŒã·ã§ã³ã«ã¯ãã¿ãŒã²ããããªã·ãŒïŒãã¿ãŒã²ãããïŒãå¿
èŠã§ããããã¯ãäžè¬çãªã¢ããªã±ãŒã·ã§ã³ã®å€§éšåã®ã«ãŒã«ãèšè¿°ããŠããŸãã ç¹å¥ãªåªåãããã«ãåºæ¬çãªãµãŒãã¹ã®åºæ¬çãªä¿è·ãååŸããŸãã ããªã·ãŒã«ãŒã«ã¯ãããã«èšèŒãããŠããªããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ããDACã®ãã¬ãŒã ã¯ãŒã¯ã§SELinuxããã®å¶éãªãã«æ©èœãããããªãã®ã§ãã
ããããããªãå®éã«ãã®SELinuxãå¿
èŠãªã®ã§ããïŒã çãã¯éåžžã«ç°¡åã§ããå Žåã«ãã£ãŠã¯ãã»ãã¥ãªãã£ãµãã·ã¹ãã ã¯å°ãªããšãäžæ£ã¢ã¯ã»ã¹ãèšé²ããããšãèš±å¯ããçæ³çã«ã¯ãããé²ãããšãã§ããŸãã ãããã«ãããéåè
ã¯ç¹å®ã®ããã»ã¹ã®ããã«æŠèª¬ããããã¬ãŒã ã¯ãŒã¯å
ã§è¡åããå¿
èŠããããŸãã

ç¬èªã®èšå®ã远å ããã«ã¯ãã³ã³ããã¹ãããã¡ã€ã³ãã¢ã¯ã»ã¹ãã¯ãã«ã䜿çšããŠæäœããŸãã ã»ãã¥ãªãã£é¢é£ã®ã€ãã³ãã¯ãã«ãŒãã«ã¬ãã«ã§SELinuxã«ãã£ãŠã€ã³ã¿ãŒã»ãããããŸãã ã»ãã¥ãªãã£ãšã³ãžã³ã®ã¡ã«ããºã ã¯ãDACã«ãŒã«ã®åŸã«æå¹ã«ãªããŸãã SELinuxã¯ãRBACïŒããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ïŒãTEïŒã¿ã€ã匷å¶ïŒãããã³ãªãã·ã§ã³ã§MLSïŒãã«ãã¬ãã«ã»ãã¥ãªãã£ïŒæ©èœãæäŸããŸãã åã·ã¹ãã ãªããžã§ã¯ãã«ã¯ãç¹å®ã®ã³ã³ããã¹ãïŒã¿ã€ãïŒããããŸãã ããªã·ãŒã®ã«ãŒã«ã«åºã¥ããŠãã»ãã¥ãªãã£ãµãã·ã¹ãã ã¯ãã®æäœã®å®è¡ãèš±å¯ãŸãã¯ãããã¯ããããã»ã¹ã¯ãšã©ãŒã¡ãã»ãŒãžãåãåããŸãã SELinuxã«ãã£ãŠè¡ããããã¹ãŠã®æ±ºå®ã¯ãAccess Vector CacheïŒAVCïŒã«ãã£ãã·ã¥ãããŸãã
SELinuxã³ã³ããã¹ãã«ã¯ããŠãŒã¶ãŒãããŒã«ãã¿ã€ããããã³ã¬ãã«ã«é¢ããæ
å ±ãå«ãŸããŠããŸãã Type Enforcementã®å±æ§ã§ããã¿ã€ããæäœããŸãã ããã»ã¹ã®ãã¡ã€ã³ãšãã¡ã€ã«ã®ã¿ã€ãã«ãã£ãŠå®çŸ©ãããŸãã SELinuxã«ãŒã«ã¯ãèš±å¯ãããã¿ã€ãã®å¯Ÿè©±ãèšè¿°ããŸãã ã¢ã¯ã»ã¹ã¯ã察å¿ããã«ãŒã«ãããå Žåã«ã®ã¿èš±å¯ãããŸãã
ãããšã¯å¥ã«ããã¡ã€ã³ç§»è¡ã®ãã¯ãããžãŒã«æ³šç®ããããšæããŸãã SELinuxã§ã¯ããœãŒã¹ãã¡ã€ã³ã®ããã»ã¹ããæ°ãããã¡ã€ã³ã®ãšã³ããªãã€ã³ãã¿ã€ãã®ãã¡ã€ã«ããéå§ããã¢ããªã±ãŒã·ã§ã³ãå®è¡ããå Žåãã¢ããªã±ãŒã·ã§ã³ããããã¡ã€ã³ããå¥ã®ãã¡ã€ã³ã«åãæ¿ããããšãã§ããŸãã
æšæºã®ã¿ãŒã²ããããªã·ãŒã¯ã200ãè¶
ããã¢ããªã±ãŒã·ã§ã³ã®ã³ã³ããã¹ãããã¡ã€ã³ãããã³ã¢ã¯ã»ã¹ã«ãŒã«ãäœæããã³èª¬æããŸãã ããªã·ãŒãæ¡åŒµããææ¡ãããã³ã³ããã¹ãã®ãã¬ãŒã ã¯ãŒã¯å
ã§è¡åããæ©äŒããããŸãã åºæ¬çãªããªã·ãŒãéçºããéãã»ãšãã©ãã¹ãŠã®äž»èŠãªãŠãŒã¹ã±ãŒã¹ãèæ
®ãããŸããã æšæºãœãªã¥ãŒã·ã§ã³ãäœæããã«ã¯ãå®è³ªçã«äœã倿Žããå¿
èŠã¯ãããŸããã
ãããã£ãŠããã³ãã¬ãŒããœãªã¥ãŒã·ã§ã³ãå®è£
ããå ŽåãSELinuxä¿è·ã¡ã«ããºã ã®äœ¿çšãæåŠããããšã¯å°ãªããšãæ£åœåãããŸããã 远å ã®ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããå Žåããã®äœ¿çšã«ã¯ããã€ãã®å°é£ãçããŸãã ã¿ã¹ã¯ã®ã³ã³ããã¹ãã§ã¯ããããã¯ã¢ãžã¥ãŒã«mod_wsgiãšZEOã§ãã SELinuxã®åäœãç¶æããã«ã¯ãèšå®ã倿Žããå¿
èŠããããŸãã
ç§ã®äŸã§ã¯ãCentOS 5.8ïŒã«ãŒãã«2.6.18-308.1.1.el5ïŒãšApache WebãµãŒããŒïŒhttpd-2.2.3-63.el5.centos.1ïŒã䜿çšããŠããŸãã PythonïŒ2.7.2ïŒãDjangoïŒ1.4ïŒãmod_wsgiïŒ3.3ïŒãããã³ZopeïŒ3.4.0ïŒã远å ã§ã€ã³ã¹ããŒã«ãããŸãã ïŒãã®ãœãããŠã§ã¢ã®å¹³å¡ãªã€ã³ã¹ããŒã«ããã»ã¹ã¯ãåå¥ã®èª¬æã«å€ããŸãããïŒ
ãŸããhttpdã®SELinuxããªã·ãŒãæ¡åŒµããå¿
èŠããããŸãã ããã©ã«ãèšå®ã¯ãããã»ã¹ã䟵害ãããå Žåã«ããã»ã¹ã確å®ã«åé¢ããããšãç®çãšããŠããŸãã ãã ãããããžã§ã¯ããžã®httpdã¢ã¯ã»ã¹ã«ã¯ãããã€ãã®å€æŽãå¿
èŠã§ãã ããªã·ãŒã®äœæè
ã¯ãã³ã³ããã¹ãã«å¶éãå ããŠã¢ããªã±ãŒã·ã§ã³ã®å®å
šãªããžãã¯ãäœæããŸããã ç°¡åãªã³ãã³ãã䜿çšãããšãã·ã¹ãã äžã®ãã¡ã€ã«ã®ããŒã¯ã¢ããã«æ
£ããã®ã«åœ¹ç«ã¡ãŸãã
semanage fcontext -l | grep httpd
ããªã·ãŒã¯ãæç€ºãããåã¿ã€ããžã®ã¢ã¯ã»ã¹ã管çããŸãã ã³ã³ããã¹ãã®å®å
šãªãªã¹ãã¯ã察å¿ããããã¥ã¢ã«ããŒãžïŒ
man httpd_selinux ïŒã«ãããŸãã ããŒã¢ã³ãšã¹ã¯ãªããããã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããhttpd_sys_content_tã¿ã€ãã«èå³ããããŸãã ãããã£ãŠãæšæºã®DACæš©éã«å ããŠããããžã§ã¯ãã®ãã£ã¬ã¯ããªãšãã¡ã€ã«ã®ã³ã³ããã¹ããæå®ããå¿
èŠããããŸãã ããã¯ã
chconã³ãã³ãã䜿çšããŠ
äžåºŠã«å®è¡ã§ããŸãã
chcon -R -t "httpd_sys_content_t" / your /ãããžã§ã¯ã
ãã ããã«ãŒã«ã䜿çšããŠã¿ã€ããèšå®ããããšããå§ãããŸãã ããã«ãããæ°ãããã¡ã€ã«ã远å ãããšãã«åŸç¶ã®èªåã¿ã€ãå²ãåœãŠãä¿èšŒãããŸãã
semanage fcontext -a -t httpd_sys_content_t "/your/project(/.*ïŒïŒ"
restorecon -R / your /ãããžã§ã¯ã
ç§ã®ãã¢ãããžã§ã¯ãã§ã¯ãZoDBããŒã¿ããŒã¹ã§Djangoã䜿çšããŠããŸãã ããŒã¿ããŒã¹ãšã®éä¿¡ææ®µãšããŠãZEOã䜿çšãããŸãã ããã¯ã¹ã¿ã³ãã¢ãã³ãœãããŠã§ã¢ã§ãããããSELinuxå
ã§æ©èœããããã«ããå¿
èŠããããŸãã åé¢ã確å®ã«ããããã«ã
httpd_tãã¡ã€ã³ã®ApacheãŠãŒã¶ãŒæš©éã§ZEOãèµ·åããããšããå§ãããŸãã ãããè¡ãã«ã¯ãããŒã¢ã³ã¢ãŒãã§èµ·åéå§ã¹ã¯ãªãããå®çŸ©ããŸãã ããã§ã¯ãã¹ã¯ãªããã®ãµã€ãºã倧ãããããã¹ã¯ãªããå
šäœã®ãªã¹ãã¯æäŸããŸããã äž»ãªãã®ã§ååã§ãã
/ usr / local / bin / zeoctl -d -s / var / run / zeo / zsock -C / etc / zeo / zeoctl.conf start
SELinuxãžã®åŸç¶ã®ã¿ã€ãç§»è¡äžã®åé¡ãåé¿ããããã«ãåæåã¹ã¯ãªãããé©åãªã³ã³ããã¹ãã«ç§»åããå¿
èŠãããããšãå¿ããªãã§ãã ããã
chcon ât "initrc_exec_t" / etc / init.d / your_init_script
æ§æãã¡ã€ã«ã§ãå¿
èŠãªãŠãŒã¶ãŒãæå®ããå¿
èŠããããŸãã
<ã©ã³ããŒ>
ããã°ã©ã / usr / local / bin / runzeo -a / var / run / zeo / zeo.socket -f / var / your_db_path / db.fs
ããŒã¢ã³ç
ãŠãŒã¶ãŒApache
</ã©ã³ããŒ>
ãœã±ããã¯ãZEOãšDjangoã®éã®ãªã³ã¯ãšããŠäœ¿çšãããŸãã httpdã¯
httpd_tãã¡ã€ã³ã§æ©èœãããããã¢ããªã±ãŒã·ã§ã³ãæ¥ç¶ã§ããããã«ãã¿ã€ããšDACæš©éãããŽã·ãšãŒãããå¿
èŠããããŸãã ãããè¡ãã«ã¯ããã£ã¬ã¯ããª/ var / run / zeoãæºåããããã«å¿
èŠãªã³ã³ããã¹ããèšå®ããŸãã -f -sã¹ã€ããã䜿çšããŠã³ã³ããã¹ãã®èªåå²ãåœãŠããœã±ããã®ã¿ã«å¶éãã-f -dã䜿çšããŠã³ã³ããã¹ãããã£ã¬ã¯ããªã«èšå®ããŸãã
semanage fcontext -a -f -d -t 'httpd_sys_script_rw_t' '/var/run/zeo(/.*ïŒïŒ'
semanage fcontext -a -f -s -t 'httpd_sys_script_rw_t' '/var/run/zeo(/.*ïŒïŒ'
restorecon âR / var /å®è¡
ZEOæ§æãã¡ã€ã«ã§ã¯ãéä¿¡ãœã±ããã®åŒ·å¶çãªå Žæãæå®ããå¿
èŠããããŸãã
<ãŒãª>
ã¢ãã¬ã¹/ var / run / zeo / zeo.socket
</ zeo >
ApacheãŠãŒã¶ãŒã®ä»£ããã«ã¢ããªã±ãŒã·ã§ã³ãå®è¡ããäºå®ãªã®ã§ãåã®æšç§»æ§ãèæ
®ããå¿
èŠããããŸãã ã¿ã€ã
httpd_tãååŸããã«ã¯ãå®è¡äžã®ããã»ã¹ãå¿
èŠã§ãã ããã©ã«ãã§ã¯ããã¡ã€ã«/ usr / local / bin / zeoctlããã³/ usr / local / bin / runzeoã«ã¯
bin_tã³ã³ããã¹ãããããŸãã ãããã¯
unconfined_tãã¡ã€ã³ããåŒã³åºããããããã³ã³ããã¹ãé·ç§»ã®ãã§ãŒã³ããã¬ãŒã¹ããå¿
èŠããããŸãã ãŸãã
/etc/init.d/ããã¹ã¯ãªãããåŒã³åºãããŸãããã®ã¹ã¯ãªããã«ã¯ãã¿ã€ã
initrc_exec_tãå²ãåœãŠãããŠããŸãã ãã®ç¶æ³ã®ç§»è¡ãã§ãŒã³ãèŠã€ããŸãã
sesearch -T -s unconfined_t -t initrc_exec_t | grep "initrc_exec_t"
èŠã€ãã£ãé·ç§»ãã§ãŒã³ã¯ã
unconfined_t initrc_exec_tïŒããã»ã¹initrc_tã®ããã«èŠã
ãŸã ã ããã»ã¹ã
initrc_tã³ã³ããã¹ããåãåãããšã
ããããŸãã ãããã£ãŠãä»åºŠã¯å¿
èŠãªã¿ã€ãã®
httpd_tã«ã€ãªããç§»è¡ãã§ãŒã³ãèŠã€ããå¿
èŠããã
ãŸã ã
sesearch -T -s initrc_t | grep "ããã»ã¹httpd_t"
æ€çŽ¢ã®çµæã¯ã
initrc_t httpd_exec_tïŒprocess httpd_t linkã«ãªããŸãã ãã®ç§»è¡ãè¡ãã«ã¯ã
httpd_exec_tã³ã³ããã¹ããå®è¡å¯èœãã¡ã€ã«ã«èšå®ããå¿
èŠããããŸãã
semanage fcontext -a -t httpd_exec_t "/ usr / local / bin / zeoctl"
semanage fcontext -a -t httpd_exec_t "/ usr / local / bin / runzeo"
restorecon -R / usr / local / bin
ããã§ãSELinuxããªã·ãŒã®httpdã®ãœã±ããã«ãœã±ããèš±å¯ã远å ããå¿
èŠããããŸãã ãããè¡ãã«ã¯ããã€ãã®æ¹æ³ããããŸãã ãŠãŒã¶ãŒã®èгç¹ããæãç°¡åãªã®ã¯ãã·ã¹ãã ãã°ããã®AVCã¡ãã»ãŒãžã«åºã¥ããŠããªã·ãŒã¢ãžã¥ãŒã«ãçæã§ããaudit2allowãŠãŒãã£ãªãã£ã§ãã ç¹å®ã®ã¢ã¯ã·ã§ã³ã®èš±å¯ã®ã¿ãäœæããããããŠãŒãã£ãªãã£ã¯æ
éã«äœ¿çšããŠãã ãã-ãã ãã
詳现ãªã¬ã€ãã¯éçºè
ã®Webãµã€ãã§æäŸãããŠããŸãã
2çªç®ã®æ¹æ³ã¯ãã¢ãžã¥ãŒã«ãæåã§äœæããã³ã³ãã€ã«ããŠãçŸåšã®ããªã·ãŒã«ã€ã³ã¹ããŒã«ããããšã§ãã ãã®æ¹æ³ã«ããããã»ã¹ã®èŠèŠåãåäžããããããã®æ¹æ³ã§ZEOçšã®ã¢ãžã¥ãŒã«ã補é ããŸãã ã¿ã€ã
httpd_sys_script_rw_tã®ãœã±ãããäœæããã³æäœ
ããæš©éã
httpd_tã«ä»äžããŸãã ãããè¡ãã«ã¯ã次ã®å
容ã®ãã¡ã€ã«/tmp/httpdAllowDjangoZEO.teãäœæããŸãã
ã¢ãžã¥ãŒã«httpdAllowDjangoZEO 1.0;
require {
ã¿ã€ãhttpd_t;
ã¿ã€ãhttpd_sys_script_rw_t;
ã¯ã©ã¹sock_fileãªã³ã¯ã
ã¯ã©ã¹sock_file setattr;
class sock_file create;
class sock_file unlink;
class sock_file write;
}
ïŒ============== httpd_t ===============
httpd_tãèš±å¯ããhttpd_sys_script_rw_tïŒsock_fileãªã³ã¯ã
httpd_tãèš±å¯httpd_sys_script_rw_tïŒsock_file setattr;
httpd_tãèš±å¯httpd_sys_script_rw_tïŒsock_file create;
httpd_tãèš±å¯httpd_sys_script_rw_tïŒsock_file unlink;
httpd_tãèš±å¯httpd_sys_script_rw_tïŒsock_file write;
次ã«ãã¢ãžã¥ãŒã«ãäœæããŠã³ã³ãã€ã«ããå¿
èŠããããŸãã ãããè¡ãã«ã¯ã
checkmoduleããã³
semodule_packageã³ãã³ãã䜿çšã
ãŸã ã çŸåšã®ããªã·ãŒã«ã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããã«ã¯ã
semoduleãŠãŒãã£ãªãã£ãå¿
èŠã§ãã
checkmodule -M -m -o / tmp / httpdAllowDjangoZEO.mod / tmp / httpdAllowDjangoZEO.te
semodule_package --outfile / tmp / httpdAllowDjangoZEO.pp --module / tmp / httpdAllowDjangoZEO.mod
semodule -i httpdAllowDjangoZEO.pp
æåŸã®ã¢ã¯ã·ã§ã³ã¯ãZoDBããŒã¿ããŒã¹ã®ä¿ç®¡å Žæã®ã³ã³ããã¹ããšZEOæ§æãã¡ã€ã«ãæ§æããããšã§ãã ãã®éçšã§ãæè¡çãª.lockãã¡ã€ã«ãäœæããå¿
èŠããããŸãã ãããã£ãŠãããŒã¿ããŒã¹ã®ä¿åå Žæã¯ããã¡ã€ã«ã®äœæãèš±å¯ããé©åãªã³ã³ããã¹ãã§ããŒã¯ããå¿
èŠããããŸãã ã
Httpd_sys_script_rw_t ãã¯ããã«é©ããŠããŸãã
semanage fcontext âa âtâ httpd_sys_script_rw_tââ / var / your_db_path ïŒ /ã* ïŒ ïŒâ
æ§æãã¡ã€ã«ã«ã¯ç¹æ®ãªã¿ã€ããhttpd_config_tãããããŸãã
semanage fcontext âa âtâ httpd_config_tââ / etc / zeo ïŒ /ã* ïŒ ïŒâ
次ã«ããµãŒãã¹ãåèµ·åããŠãæ§æããã»ã¹ãå®äºããŸãã
åŒç€Ÿãäœæããã«ãŒã«ã«ããããã³ãã«å
šäœãåé¡ãªãæ©èœããŸãã åæã«ããµãŒããŒãšãã®ãµãŒãã¹ã«è¿œå ã®SELinuxä¿è·ãæäŸããŸãã DjangoãŸãã¯ZEOã³ã³ããŒãã³ãã®ããããã䟵害ãããå Žåãæ»æè
ã¯
httpd_tãã¡ã€ã³å
ã§è¡åãããããå¶éãããã·ã¹ãã ã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã
ãã®ãããSELinuxãç¡å¹ã«ããããšãªããhttpdã®ãŠãŒã¶ãŒèšå®ãæ©èœãããããšãã§ããŸããã åæ§ã«ãã¢ããªã±ãŒã·ã§ã³ã®èŠå¶ããªã·ãŒãäœæã§ããŸãã ããã«ã¯æéãããããŸããããæ·±å»ãªçè«çãã¬ãŒãã³ã°ãå¿
èŠãããŸããã ãããã£ãŠãSELinuxãç¡å¹ã«ããªãã§ãã ããã
SELinuxãã¯ãããžãŒãããå
æ¬çã«çè§£ãã
ããã«ãFedora 13çšã®SELinuxã®ãã·ã¢èªã®èª¬æãããçè§£ããããšããå§ãããŸãã