GEN000000-LNX00800 - Use a Linux Security Module configured to limit privileges of system services - 'SELINUXTYPE = targeted or strict'

Information

Linux Security Modules such as SELinux and AppArmor can be used to provide protection from software exploits by explicitly defining the privileges permitted to each software package.

Solution

Enable one of the SELinux policies.
Edit /etc/sysconfig/selinux and set the value of the SELINUX option to 'enforcing' and SELINUXTYPE to 'targeted' or 'strict'.
Restart the system.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCE|CCE-3977-6, CCI|CCI-000366, Group-ID|V-22584, Rule-ID|SV-26978r1_rule, STIG-ID|GEN000000-LNX00800, Vuln-ID|V-22584

Plugin: Unix

Control ID: 26f0fd9b6179727e8119be37e7d9fa89f9de76d54666842e76faa79ed10736da