github linux-system-roles/selinux 1.2.0
Add ability to manage SELinux modules

latest releases: 1.7.5, 1.7.4, 1.7.3...
3 years ago

Manage SELinux modules

It's possible to maintain SELinux modules using selinux_modules variable which would contain a list of dictionaries, e.g.:

    selinux_modules:
      - { path: 'localmodule.cil', priority: '350', state: 'enabled' }
      - { name: 'unconfineduser', priority: '100', state: 'disabled' }
      - { name: 'unconfineduser', priority: '100', state: 'enabled' }
      - { name: 'localmodule', priority: '350', state: 'absent' }
  • path: filename of a module to be installed, used for installing new modules
  • name: module name, used for enabling disabled modules, disabling enabled modules, removing modules
  • priority: SELinux module priority, default is "400". "100" is used for modules installed from selinux-policy packages, "200" for other modules installed from 3rd party rpms, "300" is used by SETroubleshoot
  • state:
    • enabled: install or enable module
    • disabled: disable module
    • absent: remove module

Don't miss a new selinux release

NewReleases is sending notifications on new releases.