{"id":3878,"date":"2021-02-24T19:49:01","date_gmt":"2021-02-24T10:49:01","guid":{"rendered":"https:\/\/coeure.co.jp\/blog\/?p=3878"},"modified":"2026-04-03T11:02:29","modified_gmt":"2026-04-03T02:02:29","slug":"centos-selinux-210224","status":"publish","type":"post","link":"https:\/\/coeure.co.jp\/blog\/infrastructure\/centos\/centos-selinux-210224","title":{"rendered":"\u3010CentOS\u3011SELinux\u306e\u8a2d\u5b9a\u306b\u3064\u3044\u3066"},"content":{"rendered":"\n<p>CentOS\u306b\u306fSELinux\u3068\u3044\u3046\u4ed5\u7d44\u307f\u304c\u3042\u308a\u307e\u3059\u3002\u8a73\u7d30\u306f\u4e0b\u8a18\u306eRed Hat\u516c\u5f0f\u30b5\u30a4\u30c8\u306b\u8a18\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n\n\n<div class=\"swell-block-postLink\">\t\t\t<div class=\"p-blogCard -external\" data-type=\"type2\" data-onclick=\"clickLink\">\n\t\t\t\t<div class=\"p-blogCard__inner\">\n\t\t\t\t\t<span class=\"p-blogCard__caption\">\u516c\u5f0f\u30b5\u30a4\u30c8<\/span>\n\t\t\t\t\t<div class=\"p-blogCard__thumb c-postThumb\"><figure class=\"c-postThumb__figure\"><img decoding=\"async\" src=\"https:\/\/www.redhat.com\/profiles\/rh\/themes\/redhatdotcom\/img\/logo-rh-og-image.png\" alt=\"\" class=\"c-postThumb__img u-obf-cover\" width=\"320\" height=\"180\"><\/figure><\/div>\t\t\t\t\t<div class=\"p-blogCard__body\">\n\t\t\t\t\t\t<a class=\"p-blogCard__title\" href=\"https:\/\/www.redhat.com\/ja\/topics\/linux\/what-is-selinux\" target=\"_blank\" rel=\"noopener noreferrer\">SELinux \u3068\u306f\uff1f\u3092\u308f\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac<\/a>\n\t\t\t\t\t\t<span class=\"p-blogCard__excerpt\">SELinux \u3068\u306f Security-Enhanced Linux \u306e\u7565\u3067\u3001\u5f37\u5236\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u3092\u5b9f\u88c5\u3059\u308b Linux \u30b7\u30b9\u30c6\u30e0\u7528\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u69cb\u3067\u3059\u3002\u305d\u306e\u4ed5\u7d44\u307f\u3084\u4f7f\u3044\u65b9\u3001\u30a8\u30e9\u30fc\u306e\u5bfe\u51e6\u6cd5\u3092\u8aac\u660e\u3057\u307e\u3059\u3002<\/span>\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\n\n\n\n\n\n<p>\u3053\u306e\u516c\u5f0f\u30b5\u30a4\u30c8\u3067\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u8aac\u660e\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>SELinux (Security-Enhanced Linux) \u3068\u306f\u3001\u30b7\u30b9\u30c6\u30e0\u306b\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u306a\u30e6\u30fc\u30b6\u30fc\u3092\u3088\u308a\u8a73\u7d30\u306b\u5236\u5fa1\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u3001Linux\u00ae \u30b7\u30b9\u30c6\u30e0 \u7528\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30fb\u30a2\u30fc\u30ad\u30c6\u30af\u30c1\u30e3\u3067\u3059\u3002<\/p>\n<\/blockquote>\n\n\n\n\n\n\n\n<p>SELinux\u3092\u6709\u52b9\u306b\u3059\u308b\u304b\u3001\u7121\u52b9\u306b\u3059\u308b\u304b\u306f\u610f\u898b\u304c\u5206\u304b\u308c\u308b\u3068\u3053\u308d\u3067\u3059\u3002\u6709\u52b9\u306b\u3059\u308b\u3068\u3044\u308d\u3044\u308d\u3068\u9762\u5012\u306a\u306e\u3067\u7121\u52b9\u306b\u3057\u3066\u3044\u308b\u30b5\u30fc\u30d0\u3082\u591a\u3044\u3088\u3046\u3067\u3059\u3002<\/p>\n\n\n\n\n\n\n\n<h2 class=\"wp-block-heading\">SELinux\u306e\u72b6\u614b\u3092\u78ba\u8a8d\u3059\u308b<\/h2>\n\n\n\n<p>\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3067SELinux\u306e\u72b6\u614b\u3092\u78ba\u8a8d\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<div class=\"hcb_wrap\"><pre class=\"prism line-numbers lang-plain\"><code>$ getenforce<\/code><\/pre><\/div>\n\n\n\n\n\n\n\n<p>SELinux\u306e\u72b6\u614b\u306b\u306f\u6b21\u306e\uff13\u3064\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Enforcing\u30fb\u30fb\u30fbSELinux\u304c\u6709\u52b9\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u30dd\u30ea\u30b7\u30fc\u306b\u9055\u53cd\u3059\u308b\u30a2\u30af\u30bb\u30b9\u3092\u30ed\u30b0\u306b\u66f8\u304d\u51fa\u3057\u3001\u305d\u306e\u30a2\u30af\u30bb\u30b9\u306f\u62d2\u5426\u3055\u308c\u307e\u3059\u3002<\/li>\n\n\n\n<li>Permissive\u30fb\u30fb\u30fbSELinux\u306f\u6709\u52b9\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u30dd\u30ea\u30b7\u30fc\u306b\u9055\u53cd\u3059\u308b\u30a2\u30af\u30bb\u30b9\u3092\u30ed\u30b0\u306b\u66f8\u304d\u51fa\u3057\u307e\u3059\u304c\u3001\u305d\u306e\u30a2\u30af\u30bb\u30b9\u306f\u8a31\u53ef\u3055\u308c\u307e\u3059\u3002<\/li>\n\n\n\n<li>Disabled\u30fb\u30fb\u30fbSELinux\u304c\u7121\u52b9\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/li>\n<\/ul>\n\n\n\n\n\n\n\n<h2 class=\"wp-block-heading\">SELinux\u3092\u7121\u52b9\u306b\u3059\u308b<\/h2>\n\n\n\n<p>SELinux\u306f\u3001\u300c\/etc\/selinux\/config\u300d\u3092\u7de8\u96c6\u3059\u308b\u3053\u3068\u3067\u8a2d\u5b9a\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u30c7\u30d5\u30a9\u30eb\u30c8\u3067\u306f\u3001\u300cSELINUX=enforcing\u300d\u306b\u306a\u3063\u3066\u3044\u308b\u3068\u601d\u3044\u307e\u3059\u3002\u305d\u306e\u90e8\u5206\u3092\u300cSELINUX=disabled\u300d\u306b\u5909\u66f4\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p>vi\u30a8\u30c7\u30a3\u30bf\u3092\u4f7f\u3063\u3066\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u7de8\u96c6\u3057\u307e\u3057\u3087\u3046\u3002<\/p>\n\n\n\n<div class=\"hcb_wrap\"><pre class=\"prism line-numbers lang-plain\"><code># This file controls the state of SELinux on the system.\n# SELINUX= can take one of these three values:\n# enforcing - SELinux security policy is enforced.\n# permissive - SELinux prints warnings instead of enforcing.\n# disabled - No SELinux policy is loaded.\nSELINUX=disabled\n# SELINUXTYPE= can take one of these two values:\n# targeted - Targeted processes are protected,\n# mls - Multi Level Security protection.\nSELINUXTYPE=targeted<\/code><\/pre><\/div>\n\n\n\n<p>\u7de8\u96c6\u5f8c\u3001\u518d\u8d77\u52d5\u3059\u308b\u3053\u3068\u3067\u8a2d\u5b9a\u304c\u53cd\u6620\u3055\u308c\u307e\u3059\u3002<\/p>\n\n\n\n\n\n\n\n<h2 class=\"wp-block-heading\">SELinux\u3092\u6709\u52b9\u306b\u3059\u308b<\/h2>\n\n\n\n<p>SELinux\u3092\u6709\u52b9\u3059\u308b\u306e\u306f\u3001\u6b21\u306e\uff12\u30d1\u30bf\u30fc\u30f3\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>enforcing<\/li>\n\n\n\n<li>permissive<\/li>\n<\/ul>\n\n\n\n<p>\u300c\/etc\/selinux\/config\u300d\u3067\u8a2d\u5b9a\u3057\u307e\u3059\u3002permissive\u306b\u8a2d\u5b9a\u3059\u308b\u3068\u304d\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002<\/p>\n\n\n\n<div class=\"hcb_wrap\"><pre class=\"prism line-numbers lang-plain\"><code># This file controls the state of SELinux on the system.\n# SELINUX= can take one of these three values:\n# enforcing - SELinux security policy is enforced.\n# permissive - SELinux prints warnings instead of enforcing.\n# disabled - No SELinux policy is loaded.\nSELINUX=permissive\n# SELINUXTYPE= can take one of these two values:\n# targeted - Targeted processes are protected,\n# mls - Multi Level Security protection.\nSELINUXTYPE=targeted<\/code><\/pre><\/div>\n\n\n\n\n\n\n\n<p>enforcing\u306b\u8a2d\u5b9a\u3059\u308b\u3068\u304d\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u7de8\u96c6\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<div class=\"hcb_wrap\"><pre class=\"prism line-numbers lang-plain\"><code># This file controls the state of SELinux on the system.\n# SELINUX= can take one of these three values:\n# enforcing - SELinux security policy is enforced.\n# permissive - SELinux prints warnings instead of enforcing.\n# disabled - No SELinux policy is loaded.\nSELINUX=enforcing\n# SELINUXTYPE= can take one of these two values:\n# targeted - Targeted processes are protected,\n# mls - Multi Level Security protection.\nSELINUXTYPE=targeted<\/code><\/pre><\/div>\n\n\n\n<p>\u518d\u8d77\u52d5\u3059\u308c\u3070\u8a2d\u5b9a\u5b8c\u4e86\u3067\u3059\u3002\u3067\u306f\u3001\u4eca\u56de\u306f\u3053\u3053\u307e\u3067\u3067\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CentOS\u306b\u306fSELinux\u3068\u3044\u3046\u4ed5\u7d44\u307f\u304c\u3042\u308a\u307e\u3059\u3002\u8a73\u7d30\u306f\u4e0b\u8a18\u306eRed Hat\u516c\u5f0f\u30b5\u30a4\u30c8\u306b\u8a18\u3055\u308c\u3066\u3044\u307e\u3059\u3002 \u3053\u306e\u516c\u5f0f\u30b5\u30a4\u30c8\u3067\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u8aac\u660e\u3055\u308c\u3066\u3044\u307e\u3059\u3002 SELinux (Security-Enhanced Lin [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3773,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"swell_btn_cv_data":"","footnotes":""},"categories":[44],"tags":[],"class_list":["post-3878","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-centos"],"_links":{"self":[{"href":"https:\/\/coeure.co.jp\/blog\/wp-json\/wp\/v2\/posts\/3878","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coeure.co.jp\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coeure.co.jp\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coeure.co.jp\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coeure.co.jp\/blog\/wp-json\/wp\/v2\/comments?post=3878"}],"version-history":[{"count":13,"href":"https:\/\/coeure.co.jp\/blog\/wp-json\/wp\/v2\/posts\/3878\/revisions"}],"predecessor-version":[{"id":6405,"href":"https:\/\/coeure.co.jp\/blog\/wp-json\/wp\/v2\/posts\/3878\/revisions\/6405"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coeure.co.jp\/blog\/wp-json\/wp\/v2\/media\/3773"}],"wp:attachment":[{"href":"https:\/\/coeure.co.jp\/blog\/wp-json\/wp\/v2\/media?parent=3878"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coeure.co.jp\/blog\/wp-json\/wp\/v2\/categories?post=3878"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coeure.co.jp\/blog\/wp-json\/wp\/v2\/tags?post=3878"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}