2013-05-14 00:03:24 +00:00
|
|
|
#!/bin/bash
|
|
|
|
|
2014-03-29 03:28:22 +00:00
|
|
|
set -eux
|
|
|
|
set -o pipefail
|
2013-05-16 02:33:24 +00:00
|
|
|
|
2014-01-23 12:21:58 +00:00
|
|
|
CONFIGURED_SELINUX=$(grep ^SELINUX= /etc/selinux/config | awk -F = '{print $2}')
|
|
|
|
|
|
|
|
if [ "$CONFIGURED_SELINUX" == "enforcing" ]; then
|
|
|
|
# Without fixing selinux file labels, sshd will run in the kernel_t domain
|
|
|
|
# instead of the sshd_t domain, making ssh connections fail with
|
|
|
|
# "Unable to get valid context for <user>" error message
|
|
|
|
setfiles /etc/selinux/targeted/contexts/files/file_contexts /
|
|
|
|
FIXFILES_LOG=$(mktemp)
|
|
|
|
fixfiles -l $FIXFILES_LOG restore
|
|
|
|
cat $FIXFILES_LOG
|
|
|
|
rm $FIXFILES_LOG
|
|
|
|
else
|
|
|
|
echo "Skipping SELinux relabel, since it is not Enforcing."
|
|
|
|
echo "To relabel once the image is running, use:"
|
|
|
|
echo "setfiles /etc/selinux/targeted/contexts/files/file_contexts /"
|
|
|
|
echo "fixfiles restore"
|
|
|
|
fi
|