[Users] SELinux persistent changes on ovirt node

Fabian Deutsch fabiand at redhat.com
Thu Jan 23 11:08:24 EST 2014


Am Donnerstag, den 23.01.2014, 12:26 -0300 schrieb Francisco Pérez:
>  Hi. I have a question regarding to the ovirt node. Im trying to
> disable o set selinux in permissive mode..I have
> modified /etc/sysconfig/selinux and then use the persist command on it
> but sestats output shows the following:
> 
> 
> [root at ovirth1 ~]# sestatus 
> SELinux status:                 enabled
> SELinuxfs mount:                /selinux
> Current mode:                   enforcing
> Mode from config file:          permissive
> Policy version:                 24
> Policy from config file:        targeted
> 
> 
>  I have found that this also can be acomplished by modifying kernel's
> boot parameters So it's looks like kernel's boot parameter enforce=1
> overrides /etc/sysconfig/selinux. Where is the config file to set
> enforce=0? Can't find grub config on the node.

Hey Francisco,

the easiest way is to install Node with enforcing=0.
When you pass it at install time it is automatically persisted.

To find the boot partition take a look at the output of 
$ blkid

Also: An updated ISO is available here:
http://fedorapeople.org/~fabiand/node/3.0.4/ovirt-node-iso-3.0.4-TestDay.vdsm.el6.iso

- fabian

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: This is a digitally signed message part
URL: <http://lists.ovirt.org/pipermail/users/attachments/20140123/3e724f57/attachment.sig>


More information about the Users mailing list