Nextcloud SELinux Hardening #8

Open
opened 2021-09-27 19:14:15 +02:00 by claudiomaradonna · 0 comments
claudiomaradonna commented 2021-09-27 19:14:15 +02:00 (Migrated from gitea.it)
#INSTALLATION (Unitoo ha data spostata)
semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/vhosts/cloud.unitoo.pw/data(/.*)?'
semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/vhosts/cloud.unitoo.pw/httpdocs/config(/.*)?'
semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/vhosts/cloud.unitoo.pw/httpdocs/apps(/.*)?'
semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/vhosts/cloud.unitoo.pw/httpdocs/.htaccess'
semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/vhosts/cloud.unitoo.pw/httpdocs/.user.ini'

restorecon -Rv '/var/www/vhosts/cloud.unitoo.pw/data/'
restorecon -Rv '/var/www/vhosts/cloud.unitoo.pw/httpdocs/'

setsebool -P  httpd_unified  off

#UNINSTALL
semanage fcontext -d '/var/www/vhosts/cloud.unitoo.pw/data(/.*)?'
semanage fcontext -d '/var/www/vhosts/cloud.unitoo.pw/httpdocs/config(/.*)?'
semanage fcontext -d '/var/www/vhosts/cloud.unitoo.pw/httpdocs/apps(/.*)?'
semanage fcontext -d '/var/www/vhosts/cloud.unitoo.pw/httpdocs/.htaccess'
semanage fcontext -d '/var/www/vhosts/cloud.unitoo.pw/httpdocs/.user.ini'

restorecon -Rv '/var/www/vhosts/cloud.unitoo.pw/data/'
restorecon -Rv '/var/www/vhosts/cloud.unitoo.pw/httpdocs/'

setsebool httpd_unified on
```bash #INSTALLATION (Unitoo ha data spostata) semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/vhosts/cloud.unitoo.pw/data(/.*)?' semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/vhosts/cloud.unitoo.pw/httpdocs/config(/.*)?' semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/vhosts/cloud.unitoo.pw/httpdocs/apps(/.*)?' semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/vhosts/cloud.unitoo.pw/httpdocs/.htaccess' semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/vhosts/cloud.unitoo.pw/httpdocs/.user.ini' restorecon -Rv '/var/www/vhosts/cloud.unitoo.pw/data/' restorecon -Rv '/var/www/vhosts/cloud.unitoo.pw/httpdocs/' setsebool -P httpd_unified off #UNINSTALL semanage fcontext -d '/var/www/vhosts/cloud.unitoo.pw/data(/.*)?' semanage fcontext -d '/var/www/vhosts/cloud.unitoo.pw/httpdocs/config(/.*)?' semanage fcontext -d '/var/www/vhosts/cloud.unitoo.pw/httpdocs/apps(/.*)?' semanage fcontext -d '/var/www/vhosts/cloud.unitoo.pw/httpdocs/.htaccess' semanage fcontext -d '/var/www/vhosts/cloud.unitoo.pw/httpdocs/.user.ini' restorecon -Rv '/var/www/vhosts/cloud.unitoo.pw/data/' restorecon -Rv '/var/www/vhosts/cloud.unitoo.pw/httpdocs/' setsebool httpd_unified on ```
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: unitoo/configurations#8
No description provided.