Enable the selinuxuser_ping SELinux Boolean
An XCCDF Rule
Description
By default, the SELinux boolean selinuxuser_ping
is enabled.
If this setting is disabled, it should be enabled as it allows confined users
to use ping and traceroute which is helpful for network troubleshooting.
To enable the selinuxuser_ping
SELinux boolean, run the following command:
$ sudo setsebool -P selinuxuser_ping on
- ID
- xccdf_org.ssgproject.content_rule_sebool_selinuxuser_ping
- Severity
- Medium
- Updated
Remediation - Ansible
- name: Gather the package facts
package_facts:
manager: auto
tags:
- enable_strategy
- low_complexity
Remediation - Shell Script
# Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then
if ! rpm -q --quiet "python3-libsemanage" ; then
yum install -y "python3-libsemanage"
fi