First page Back Continue Last page Overview

 

SELinux

 
  • Each process or object (file, directory, network socket also has a SELinux context.

    • identity:role:domain/type
  • The SELinux policy controls

    • what identities can use which roles
    • what roles can enter which domains
    • what domains can access which types