Skip to content

Commit abd64ed

Browse files
authored
selinux for sap (#584)
* selinux for sap * tech feedback * jana's review
1 parent c2a0b2a commit abd64ed

File tree

4 files changed

+24
-1
lines changed

4 files changed

+24
-1
lines changed

DC-SAP-SELinux

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# This file originates from the project https://github.com/openSUSE/doc-kit
2+
# This file can be edited downstream.
3+
4+
MAIN="SELinux.asm.xml"
5+
# Point to the ID of the <structure> of your assembly
6+
SRC_DIR="articles"
7+
IMG_SRC_DIR="images"
8+
9+
PROFOS="sles4sap"
10+
PROFCONDITION="16.0"
11+
#PROFCONDITION="suse-product;beta"
12+
#PROFCONDITION="community-project"
13+
14+
STYLEROOT="/usr/share/xml/docbook/stylesheet/suse2022-ns"
15+
FALLBACK_STYLEROOT="/usr/share/xml/docbook/stylesheet/suse-ns"

concepts/selinux-modes.xml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,9 @@
4242
</listitem>
4343
</varlistentry>
4444
</variablelist>
45-
<para>The default in &productnameshort; &productnumber; is <literal>enforcing</literal> mode.</para>
45+
46+
<para os="sles">The default in &productnameshort; &productnumber; is <literal>enforcing</literal> mode.</para>
47+
<para> <phrase os="sles4sap"> The default in &productname; &productnumber; is enabled in <literal>permissive</literal> mode, if &sap; patterns are installed. </phrase></para>
4648
<para>
4749
For information about switching between &selnx; modes, refer to
4850
<xref linkend="selinux-switching-modes"/>.

concepts/selinux-policy.xml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,4 +39,8 @@
3939
This allows the administrator to customize policies for different parts of the
4040
system.
4141
</para>
42+
<para os="sles4sap"><emphasis role="bold">About &selnx; for &productname; &productnumber;</emphasis></para>
43+
<para os="sles4sap"> The<literal>selinux-policy-sapenablement</literal> package is for &selnx; policy changes for running &sap;.
44+
Currently it sets the settings that are needed, but still sets &selnx; to <literal>permissive</literal> mode.
45+
This package is installed by default.</para>
4246
</topic>

tasks/selinux-packages.xml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -68,6 +68,8 @@
6868
Advanced policy development requires additional <literal>-devel</literal>
6969
packages, which can be installed by:
7070
</para>
71+
72+
7173
<screen os="sles;sles4sap">
7274
&prompt.sudo;<command>zypper install selinux-policy-devel policycoreutils-devel</command>
7375
</screen>

0 commit comments

Comments
 (0)