An XCCDF Group - A logical subset of the XCCDF Benchmark
setroubleshoot-plugins
$ sudo dnf remove setroubleshoot-plugins
setroubleshoot-server
$ sudo dnf remove setroubleshoot-server
setroubleshoot
$ sudo dnf remove setroubleshoot
/etc/selinux
$ sudo chgrp root /etc/selinux
$ sudo chown root /etc/selinux
$ sudo chmod 0755 /etc/selinux
/etc/sestatus.conf
$ sudo chgrp root /etc/sestatus.conf
$ sudo chown root /etc/sestatus.conf
$ sudo chmod 0644 /etc/sestatus.conf
targeted
/etc/selinux/config
SELINUXTYPE=
mls
SELINUX=
deny_execmem
$ sudo setsebool -P deny_execmem
polyinstantiation_enabled
$ sudo setsebool -P polyinstantiation_enabled
secure_mode_insmod
$ sudo setsebool -P secure_mode_insmod
selinuxuser_execheap
$ sudo setsebool -P selinuxuser_execheap off
selinuxuser_execstack
$ sudo setsebool -P selinuxuser_execstack off
ssh_sysadm_login
$ sudo setsebool -P ssh_sysadm_login off