1.6.1.3 Ensure the SELinux state is enforcing - sestatus

Information

Set SELinux to enable when the system is booted.

Rationale:

SELinux must be enabled at boot time to ensure that the controls it provides are in effect at all times.

Solution

Edit the /etc/selinux/config file to set the SELINUX parameter:
Example vim /etc/selinux/config

SELINUX=enforcing

Notes:

This Benchmark recommendation maps to:

Red Hat Enterprise Linux 7 Security Technical Implementation Guide:

Version 2, Release: 3 Benchmark Date: 26 Apr 2019



Vul ID: V-71989

Rule ID: SV-86613r3_rule

STIG ID: RHEL-07-020210

Severity: CAT I

See Also

https://workbench.cisecurity.org/files/2688

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CSCv7|14.6

Plugin: Unix

Control ID: dba3f3358c1754209827c9d86fdacba3cab565e510bb1e36ca015da178ed2f33