Red Hat Training

A Red Hat training course is available for RHEL 8

13.2. fapolicyd 배포

RHEL에 fapolicyd 프레임워크를 배포하려면 다음을 수행합니다.

절차

  1. fapolicyd 패키지를 설치합니다.

    # yum install fapolicyd
  2. fapolicyd 서비스를 활성화하고 시작합니다.

    # systemctl enable --now fapolicyd

검증

  1. fapolicyd 서비스가 올바르게 실행되고 있는지 확인합니다.

    # systemctl status fapolicyd
    ● fapolicyd.service - File Access Policy Daemon
       Loaded: loaded (/usr/lib/systemd/system/fapolicyd.service; enabled; vendor p>
       Active: active (running) since Tue 2019-10-15 18:02:35 CEST; 55s ago
      Process: 8818 ExecStart=/usr/sbin/fapolicyd (code=exited, status=0/SUCCESS)
     Main PID: 8819 (fapolicyd)
        Tasks: 4 (limit: 11500)
       Memory: 78.2M
       CGroup: /system.slice/fapolicyd.service
               └─8819 /usr/sbin/fapolicyd
    
    Oct 15 18:02:35 localhost.localdomain systemd[1]: Starting File Access Policy D>
    Oct 15 18:02:35 localhost.localdomain fapolicyd[8819]: Initialization of the da>
    Oct 15 18:02:35 localhost.localdomain fapolicyd[8819]: Reading RPMDB into memory
    Oct 15 18:02:35 localhost.localdomain systemd[1]: Started File Access Policy Da>
    Oct 15 18:02:36 localhost.localdomain fapolicyd[8819]: Creating database
  2. root 권한이 없는 사용자로 로그인하고 fapolicyd 가 작동하는지 확인합니다. 예를 들면 다음과 같습니다.

    $ cp /bin/ls /tmp
    $ /tmp/ls
    bash: /tmp/ls: Operation not permitted