Enable the selinuxuser_ping SELinux Boolean
An XCCDF Rule
Description
By default, the SELinux boolean selinuxuser_ping
is enabled.
If this setting is disabled, it should be enabled as it allows confined users
to use ping and traceroute which is helpful for network troubleshooting.
To enable the selinuxuser_ping
SELinux boolean, run the following command:
$ sudo setsebool -P selinuxuser_ping on
- ID
- xccdf_org.ssgproject.content_rule_sebool_selinuxuser_ping
- Severity
- Medium
- References
- Updated
Remediation - Ansible
- name: Enable the selinuxuser_ping SELinux Boolean - Ensure libsemanage-python Installed
package:
name: libsemanage-python
state: present
when: ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
tags:
Remediation - Shell Script
# Remediation is applicable only in certain platforms
if [ ! -f /.dockerenv ] && [ ! -f /run/.containerenv ]; then
if ! rpm -q --quiet "libsemanage-python" ; then
yum install -y "libsemanage-python"
fi