Skip to main content

Posts

Showing posts with the label security

Red Hat SELinux–How to Enable/Disable

Here is the quick how-to for enabling and disabling SELinux on a Red Hat Enterprise Linux server temporarily and permanently.  There are 3 modes available with the SELinux- Enforcing – SELinux policy is enforced and access is denied based on the SELinux policy rules. Permissive – SELinux policy is not enforced .  Access is is not denied, but what would have been denied if it were enforced will be logged. Disabled – SELinux is disabled completely.  only DAC rules are used.  To permanently disable SELinux on the system, update ‘ SELINUX=disabled ’ in /etc/selinux/config file and reboot the system for the change to take effect To change between the modes temporarily during run time, use the /usr/sbin/setenforce command with the appropriate mode /usr/sbin/setenforce 1 will set the mode to Enforced /usr/sbin/setenforce 0 will set the mode to Permissive /usr/sbin/getenforce to display the current mode Refer RHEL 6 SELinux guide for more detailed informa...

Cryptographic Sum Command

Users often use the sum command to generate a checksum to verify the integrity of a file. However, it is possible for two distinct files to generate the same checksum. A cryptographic sum command, csum , has been implemented in AIX 5L Version 5.3 that offers a more reliable tool to verify file integrity. This command allows users to generate message digests using the AIX Cryptographic Library. The new, cryptographic, checksum is considered more secure than the old mechanism. While it is reasonably straightforward to construct data that will match the checksum generated by the sum command; it is computationally infeasible to construct data to generate a known cryptographic checksum, as provided by csum . csum allows users the option to select the algorithm that they prefer, including both MD5 and SHA-1, which are considered secure. It is estimated that the order of 2**64 operations would be required to derive two different files, which generate the same MD5 message digest. Also, t...