Ce contenu n'est pas disponible dans la langue sélectionnée.
26.2. Configuration Examples
26.2.1. Mapping SELinux users to IdM users Copier lienLien copié sur presse-papiers!
Copier lienLien copié sur presse-papiers!
The following procedure shows how to create a new SELinux mapping and how to add a new IdM user to this mapping.
Procedure 26.1. How to Add a User to an SELinux Mapping
- To create a new SELinux mapping, enter the following command where
SELinux_mappingis the name of the new SELinux mapping and the--selinuxuseroption specifies a particular SELinux user:ipa selinuxusermap-add SELinux_mapping --selinuxuser=staff_u:s0-s0:c0.c1023
~]$ ipa selinuxusermap-add SELinux_mapping --selinuxuser=staff_u:s0-s0:c0.c1023Copy to Clipboard Copied! Toggle word wrap Toggle overflow - Enter the following command to add an IdM user with the
tuseruser name to the SELinux mapping:ipa selinuxusermap-add-user --users=tuser SELinux_mapping
~]$ ipa selinuxusermap-add-user --users=tuser SELinux_mappingCopy to Clipboard Copied! Toggle word wrap Toggle overflow - To add a new host named
ipaclient.example.comto the SELinux mapping, enter the following command:ipa selinuxusermap-add-host --hosts=ipaclient.example.com SELinux_mapping
~]$ ipa selinuxusermap-add-host --hosts=ipaclient.example.com SELinux_mappingCopy to Clipboard Copied! Toggle word wrap Toggle overflow - The
tuseruser gets thestaff_u:s0-s0:c0.c1023label when logged in to the ipaclient.example.com host:id -Z staff_u:staff_r:staff_t:s0-s0:c0.c1023
[tuser@ipa-client]$ id -Z staff_u:staff_r:staff_t:s0-s0:c0.c1023Copy to Clipboard Copied! Toggle word wrap Toggle overflow