Security-Enhanced Linux
Security-Enhanced Linux (SELinux) is a Linux kernel security solution that
-
incorporates a strong, flexible Mandatory Access Control (MAC) architecture into Cisco IOS XE platforms
-
provides enhanced mechanisms to enforce information separation based on confidentiality and integrity requirements, and
-
confines user programs and system services to minimum privilege required to perform their assigned functionality.
SELinux functionality and modes
SELinux addresses threats of tampering and bypassing of application security mechanisms and enables the confinement of damage that malicious or flawed applications can cause.
SELinux enforces mandatory access control policies that confine user programs and system services to the minimum privilege required to perform their assigned functionality. This reduces or eliminates the ability of these programs and daemons to cause harm when compromised (for example, through buffer overflows or misconfigurations). This is a practical implementation of principle of least privilege by enforcing MAC on Cisco IOS XE platforms. This confinement mechanism works independently of the traditional Linux access control mechanisms. SELinux allows you to define policies to control the access from an application process to any resource object, thereby allowing for the clear definition and confinement of process behavior.
SELinux can operate in two modes when enabled on a system:
-
Permissive Mode: In Permissive mode, SELinux does not enforce the policy, and only generates system logs for any denials caused by violation of the resource access policy. The operation is not denied, but only logged for resource access policy violation.
-
Enforcing Mode: In Enforcing mode, the SELinux policy is enabled and enforced. The Enforcing mode denies resource access based on the access policy rules, and generates system logs.
SELinux is enabled in the Enforcing mode by default on supported Cisco IOS XE platforms. In the Enforcing mode, any system resource access that does not have the necessary allow policy is treated as a violation, and the operation is denied. The violating operation fails when a denial occurs, and system logs are generated. In Enforcing mode, the solution works in access-violation prevention mode.
Note |
By default, SELinux is in the Enforcing mode. |
Configure SELinux in the EXEC mode
Procedure
|
Step 1 |
Enable privileged EXEC mode. Example:
Enter the password if prompted. |
|
Step 2 |
Enter global configuration mode. Example:
|
|
Step 3 |
Enable the internal commands of the network-based services. Example:
|
|
Step 4 |
Exit from the global configuration mode. Example:
|
|
Step 5 |
Configure SELinux in the EXEC mode. Example:
Example:
Available modes are default, enforcing, or permissive. |
Configure SELinux in the global configuration mode
This task enables you to set up SELinux security policies on the device to enhance system security through access controls.
SELinux (Security-Enhanced Linux) provides mandatory access controls that can be configured in either enforcing or permissive mode. Use this procedure when you need to establish or modify SELinux security policies on your device.
Procedure
|
Step 1 |
Enter global configuration mode. Example:
|
|
Step 2 |
Enable the internal commands of the network-based services. Example:
|
|
Step 3 |
Configure SELinux policy. Example:
|
SELinux is now configured with the specified policy mode. The system will apply the selected security enforcement level to control access to system resources.
Examples for SELinux
Provides examples of system log output when changing SELinux modes between Enforcing and Permissive states.
This example shows the output for changing the mode from Enforcing to Permissive:
"*Oct 20 21:44:03.609: %IOSXE-1-PLATFORM: R0/0: SELINUX_MODE_PROG: Platform Selinux confinement mode downgraded to permissive!"
This example shows the output for changing the mode from Permissive to Enforcing:
"*Oct 20 21:44:34.160: %IOSXE-1-PLATFORM: R0/0: SELINUX_MODE_PROG: Platform Selinux confinement mode upgraded to enforcing!"
Note |
If you change the SELinux mode, the change is considered as a system security event, and a system log message is generated. |
SELINUX syslog message reference
Provides reference information for SELINUX syslog messages including message details, explanations, components, and recommended actions for troubleshooting security policy violations.
|
Facility-Severity-Mnemonic |
%SELINUX-1-VIOLATION |
|---|---|
|
Severity-Meaning |
Alert Level Log |
|
Message |
N/A |
|
Message Explanation |
Resource access was made by the process for which a resource access policy does not exist. The operation was flagged, and resource access was denied. A system log was generated with information that process resource access has been denied. |
|
Component |
SELINUX |
|
Recommended Action |
Contact Cisco TAC with these relevant information as attachments:
|
These examples display sample syslog messages:
Example 1:
*Nov 14 00:09:04.943: %SELINUX-1-VIOLATION: R0/0: audispd: type=AVC
msg=audit(1699927057.934:129): avc: denied { getattr } for pid=5899 comm="ls"
path="/root/test" dev="rootfs" ino=25839
scontext=system_u:system_r:polaris_iosd_t:s0
tcontext=system_u:object_r:admin_home_t:s0 tclass=file permissive=0
Example 2:
*Nov 14 00:09:04.947: %SELINUX-1-VIOLATION: R0/0: audispd: t type=AVC
msg=audit(1699927198.486:130): avc: denied { write } for pid=6012 comm="echo"
path="/root/test" dev="rootfs" ino=25839
scontext=system_u:system_r:polaris_iosd_t:s0
tcontext=system_u:object_r:admin_home_t:s0 tclass=file permissive= 0
Verify count of denials
To verify the count of denials, use this command:
Device# show platform software audit summary
===================================
AUDIT LOG ON chassis 1 route-processor 0
-----------------------------------
AVC Denial count: 6
Verify SELinux enablement
To verify SELinux enablement, use this command:
Device# show platform software selinux
=========================================
IOS-XE SELINUX STATUS
=========================================
SElinux Status : Enabled
Current Mode : Enforcing
Config file Mode : Enforcing
Feedback