5.5.2. Configuring Booleans
Run the
setsebool
utility in the setsebool boolean_name on/off
form to enable or disable Booleans.
The following example demonstrates configuring the
httpd_can_network_connect_db
Boolean:
- By default, the
httpd_can_network_connect_db
Boolean is off, preventing Apache HTTP Server scripts and modules from connecting to database servers:~]$
getsebool httpd_can_network_connect_db
httpd_can_network_connect_db --> off - To temporarily enable Apache HTTP Server scripts and modules to connect to database servers, run the
setsebool httpd_can_network_connect_db on
command as the Linux root user. - Use the
getsebool httpd_can_network_connect_db
command to verify the Boolean is enabled:~]$
getsebool httpd_can_network_connect_db
httpd_can_network_connect_db --> onThis allows Apache HTTP Server scripts and modules to connect to database servers. - This change is not persistent across reboots. To make changes persistent across reboots, run the
setsebool -P boolean-name on
command as the Linux root user:[7]~]#
setsebool -P httpd_can_network_connect_db on
[7]
To temporarily revert to the default behavior, as the Linux root user, run the
setsebool httpd_can_network_connect_db off
command. For changes that persist across reboots, run the setsebool -P httpd_can_network_connect_db off
command.