1.4.1 Enable SELinux in /etc/grub.conf - selinux != 0

Information

Configure SELINUX to be enabled at boot time and verify that it has not been overwritten by the grub boot parameters

Rationale:

SELinux must be enabled at boot time in /etc/grub.conf to ensure that the controls it provides are not overwritten.

Solution

Remove all instances of selinux=0 and enforcing=0 from /etc/grub.conf.

Default Value:

OS Default: No

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CSCv7|14.6

Plugin: Unix

Control ID: d58c1579077e6f2141d96698df85837c1e7556053fe0a049c876f66e5c694b31