1.6.1.1 Ensure SELinux is not disabled in bootloader configuration

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

SELinux must be enabled at boot time in your grub configuration to ensure that the controls it provides are not overridden.

Solution

Edit /etc/default/grub and remove all instances of selinux=0 and enforcing=0 from all CMDLINE_LINUX parameters: GRUB_CMDLINE_LINUX_DEFAULT='quiet'GRUB_CMDLINE_LINUX='' Run the following command to update the grub2 configuration: # grub2-mkconfig > /boot/grub2/grub.cfg

Item Details

Category: ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-3, 800-53|SI-7, CSCv6|14.4

Plugin: Unix

Control ID: 63e98fb8115951dcfbc9bf10eada6f95f7e61c041d3a1a45f737633999a8e028