/selinux_file_protection

Demo of creating SELinux types and mapping those to roles. Mapping logins to roles to prevent data access.

Primary LanguageJinja

selinux_file_protection

This repo contains the demo code to create several selinux types and map them to selinux users. It is designed to be used with Identity Management in RHEL to provide a very simple example of centralized mapping of users to selinux users and protecting the data mapped to these types from inappropriate access.

This is a demo of capability rather than a prescriptive model of how to implement this in production. A production model for implementing SELinux types is out of scope and should only be created in the context of a project engaging SELinux experts and with a thorough understanding of the data access requirements for the target environment.