Mastering Security-Enhanced Linux (SELinux)
5h 20mBeginner2024-10-22
Authors

Pearson

Sander van Vugt
Course details
Becoming a master at using Security-Enhanced Linux (SELinux) can set you apart as a developer or DevOps engineer and open up new opportunities to grow your career. SELinux is a valuable addition to the standard Linux security options that makes your Linux distribution secure. This course demonstrates the basics of SELinux before diving deeper into more advanced topics such as Multi-Level Security (MLS), Multi-Category Security (MCS), managing SELinux with Ansible, and using SELinux in containerized environments. Along the way, test out your new SELinux skills in real time in the exercise challenges at the end of each section. This course is also a full resource for learners who want to thoroughly understand SELinux while preparing for any Red Hat Enterprise Linux-related exam.
Learning objectives
Troubleshoot common problems in SELinux.
Make your application work with SELinux
Implement military-grade security using SELinux Multi-Level Security (MLS) and Multi-Category Security (MCS).
Configure SELinux for containers and secure a containerized environment by adding SELinux.
Manage SELinux with Ansible.
Learning objectives
Troubleshoot common problems in SELinux.
Make your application work with SELinux
Implement military-grade security using SELinux Multi-Level Security (MLS) and Multi-Category Security (MCS).
Configure SELinux for containers and secure a containerized environment by adding SELinux.
Manage SELinux with Ansible.
Skills covered
LinuxServer AdministrationIncident ResponseCybersecurityNetwork and System AdministrationOpen SourceOne-Off
Concepts
0. Introduction
- 01 - Mastering Security-Enhanced Linux (SELinux) - Introduction
Lesson 1 - Mandatory Access Control
- 02 - Module 1 - SELinux fundamentals introduction
- 03 - Learning objectives
- 04 - Working of SELinux
- 05 - Requiring mandatory access control
- 06 - Understanding SELinux and discretionary access control
- 07 - Lesson 1 - Lab exploring SELinux settings
- 08 - Lesson 1 - Lab solution exploring SELinux settings
Lesson 2 - Enabling SELinux
- 09 - Learning objectives
- 10 - Managing states and modes on Red Hat
- 11 - Installing SELinux on Ubuntu
- 12 - Understanding policies
- 13 - Lesson 2 - Lab managing SELinux states
- 14 - Lesson 2 - Lab solution managing SELinux states
Lesson 3 - Understanding Context Labels
- 15 - Learning objectives
- 16 - Showing context labels
- 17 - Understanding when to set context labels
- 18 - Using the audit.log to examine issues
- 19 - Understanding context inheritance
- 20 - Lesson 3 - Lab examining SELinux events
- 21 - Lesson 3 - Lab solution examining SELinux events
Lesson 4 - Managing Context Labels
- 22 - Learning objectives
- 23 - Finding the right context
- 24 - Setting context on files
- 25 - Setting context on ports
- 26 - Using customisable types
- 27 - Configuring a non-default Apache DocumentRoot
- 28 - Lesson 4 - Lab running SSH on port 443
- 29 - Lesson 4 - Lab solution running SSH on port 443
Lesson 5 - Using Booleans
- 30 - Learning objectives
- 31 - Understanding booleans
- 32 - Using booleans
- 33 - Finding booleans
- 34 - Lesson 5 - Lab configuring vsftpd for anonymous uploads
- 35 - Lesson 5 - Lab solution configuring vsftpd for anonymous uploads
Lesson 6 - Troubleshooting SELinux
- 36 - Module 2 - Analysing SELinux introduction
- 37 - Learning objectives
- 38 - Troubleshooting SELinux issues
- 39 - Understanding the audit logs
- 40 - Understanding dontaudit rules
- 41 - Using audit2allow
- 42 - Using sealert
- 43 - Loading SELinux manually
- 44 - Lesson 6 - Lab troubleshooting SELinux
- 45 - Lesson 6 - Lab solution troubleshooting SELinux
Lesson 7 - Analysing Booleans and Rules
- 46 - Learning objectives
- 47 - Analysing the policy
- 48 - Terminology
- 49 - Using sesearch
- 50 - Using seinfo
- 51 - Finding what a domain can do
- 52 - Analysing booleans
- 53 - Analysing transition rules
- 54 - Lesson 7 - Lab investigating booleans
- 55 - Lesson 7 - Lab solution investigating booleans
Lesson 8 - SELinux Modules
- 56 - Module 3 - Using custom applications with SELinux introduction
- 57 - Learning objectives
- 58 - Managing modules
- 59 - Writing custom modules
- 60 - Generating custom modules
- 61 - Lesson 8 - Lab enabling your application with modules
- 62 - Lesson 8 - Lab solution enabling your application with modules
Lesson 9 - Making Any Application Work with SELinux
- 63 - Learning objectives
- 64 - Understanding options for running custom applications
- 65 - Using unconfined domains
- 66 - Using run-on to run applications with a specific context
- 67 - Using sepolgen to generate application policy modules
- 68 - Lesson 9 - Lab running any application on an SELinux system
- 69 - Lesson 9 - Lab solution running any application on an SELinux system
Lesson 10 - SELinux Users
- 70 - Module 4 - Military grade security with SELinux users and MLS introduction
- 71 - Learning objectives
- 72 - Understanding users and roles
- 73 - Mapping Linux users to SELinux users
- 74 - Using booleans to manage SELinux users
- 75 - Restricting root
- 76 - Lesson 10 - Lab creating a kiosk user
- 77 - Lesson 10 - Lab solution creating a kiosk user
Lesson 11 - Using Multi-Level Security (MLS)
- 78 - Learning objectives
- 79 - Understanding MLS and MCS
- 80 - Enabling an MLS policy
- 81 - Creating a user with a clearance level
- 82 - Understanding what needs to be done on directories
- 83 - Lesson 11 - Lab using MLS
- 84 - Lesson 11 - Lab solution using MLS
Lesson 12 - Using Multi-Category Security (MCS)
- 85 - Learning objectives
- 86 - Understanding MCS
- 87 - Grouping users and applications with MCS
- 88 - Combining MLS and MCS
- 89 - Lesson 12 - Lab configuring MCS
- 90 - Lesson 12 - Lab solution configuring MCS
Lesson 13 - SELinux and Containers
- 91 - Module 5 - SELinux, containers, and Ansible introduction
- 92 - Learning objectives
- 93 - Understanding container SELinux needs
- 94 - Configuring container storage access
- 95 - Using udica to configure container access
- 96 - Lesson 13 - Lab configuring SELinux for containers
- 97 - Lesson 13 - Lab solution configuring SELinux for containers
Lesson 14 - Using Ansible to Manage SELinux
- 98 - Learning objectives
- 99 - Using SELinux Ansible modules
- 100 - Using the RHEL system role to manage SELinux
- 101 - Lesson 14 - Lab using Ansible to manage SELinux
- 102 - Lesson 14 - Lab solution using Ansible to manage SELinux
Summary
- 103 - Mastering Security-Enhanced Linux (SELinux) - Summary