1.4.1 Enable SELinux in /etc/grub.conf - selinux != 0

Information

Configure SELINUX to be enabled at boot time and verify that it has not been overwritten by the grub boot parameters

Rationale:

SELinux must be enabled at boot time in /etc/grub.conf to ensure that the controls it provides are not overwritten.

Solution

Remove all instances of selinux=0 and enforcing=0 from /etc/grub.conf.

Default Value:

OS Default: No

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CSCv7|14.6

Plugin: Unix

Control ID: 0c08fbe6de64e65f67e0828d634a6d257b7308417d5de4a401c2c8f1479645e2