Uploaded image for project: 'RHEL Documentation'
  1. RHEL Documentation
  2. RHELDOCS-17860

Change procedure to disable selinux

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • Red Hat Enterprise Linux
    • Unspecified
    • Unspecified
    • Unspecified

      Document link:

      https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/system_design_guide/using_selinux#Enabling_and_Disabling_SELinux-Disabling_SELinux_changing-selinux-states-and-modes

       

      Section number and name:

      17.2.5 Disabling SELinux

      Describe the issue:

      As per KCS 4890471 and RHEL8.4 release note ("Runtime disabling SELinux using /etc/selinux/config is now deprecated" in https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html-single/8.4_release_notes/index#deprecated-functionality_security), we should show procedure that disables SELinux with selinux=0 in kernel boot parameter instead of SELINUX=disabled in /etc/selinux/config.

       

      /etc/selinux/config has been deprecated since RHEL8.4 and it has a risk to cause kernel panic as a warning mentioned in this Chapter.

       

      Suggestions for improvement:

      Currently, 17.2.5. Disabling SELinux has a Warning section and procedure on how to disable selinux with SELINUX=disabled.

       

      I suggests that ...

      1. Remove the current Warning section
      2. Show the procedure using selinux=0 in kernel boot parameter.
      3. Create a new Warning section that explains /etc/selinux/config might cause kernel panic and this procedure has been already deprecated since RHEL8.4.

       

      Additional information:

            Unassigned Unassigned
            rhn-support-ryasuoka Ryosuke Yasuoka
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: