Class | selinux::selinux |
In: |
/tmp/puppet/modules/selinux/manifests/init.pp
|
Parent: |
Class: selinux
File: /etc/puppet/modules/selinux/manifests/init.pp
Description:
This class ensures that selinux is properly configured to be enforcing by checking that it is set in /etc/sysconfig/selinux and /etc/grub.conf
Guide Reference:
2.4.2 2.4.3.2 2.4.2.1
CCE Reference:
CCE-3624-4, CCE-3668-1, CCE-3977-6
TODO:
Determine if we need to uninstall/disable any setroubleshoot helper services
GuideSection 2.4.2 Ensure selinux=0 or enforcing=0 are not in grub.conf
GuideSection 2.4.2 and 2.4.2.1 turn on selinux