| semanage-login(8) | semanage-login(8) |
semanage-login - SELinux Policy Management linux user to SELinux User mapping tool
semanage login [-h] [-n] [-N] [-S STORE] [ --add -s SEUSER -r RANGE LOGIN | --delete LOGIN | --deleteall | --extract | --list [-C] | --modify -s SEUSER -r RANGE LOGIN ]
semanage is used to configure certain elements of SELinux policy without requiring modification to or recompilation from policy sources. semanage login controls the mapping between a Linux User and the SELinux User. It can be used to turn on confined users. For example you could define that a particular user or group of users will login to a system as the user_u user. Prefix the group name with a '%' sign to indicate a group name.
Modify the default user on the system to the guest_u user # semanage login -m -s guest_u __default__ Assign gijoe user on an MLS machine a range and to the staff_u user # semanage login -a -s staff_u -rSystemLow-Secret gijoe Assign all users in the engineering group to the staff_u user # semanage login -a -s staff_u %engineering
This man page was written by Daniel Walsh <dwalsh@redhat.com>
| 20130617 |