Memory hook: Identity, mode bits and labels must all agree.
Must remember
useradd,usermod,userdel,groupaddandgroupmodmanage local accounts.id USERverifies identity and supplementary groups;getent passwd USERrespects configured identity sources. Useusermod -aGto append group membership; omitting-acan replace existing supplementary groups.passwdchanges passwords andchage -l USERinspects aging. Locking a password does not necessarily revoke SSH keys or existing sessions. Usesudofor delegated privilege; edit sudoers throughvisudoto check syntax.- For a regular file, r/w/x mean read/change/execute. For a directory, they mean list names/change entries/traverse. Deleting a file depends mainly on its parent directory permissions, with sticky-bit rules when present.
chmod 640 filegives owner rw, group r, others none.chown user:group filechanges ownership. Setgid on a shared directory helps new files inherit its group; sticky limits removal of other users' entries.umaskremoves default permission bits; it does not add execute permission to ordinary newly created files.- SELinux adds mandatory policy checks beyond Unix permissions. Enforcing blocks prohibited actions; permissive records denials without enforcing them. Inspect
getenforce,ls -Z,ps -eZand audit messages. restoreconrestores configured labels.semanage fcontextdefines persistent path-label rules;chconalone may be overwritten by relabeling.semanage portmaps a nonstandard service port to its allowed type.getseboolinspects booleans;setsebool -Ppersists a supported policy toggle.
Practical drill: create a shared directory for a group, then explain why a web service still needs the correct SELinux type even when Unix permissions allow reading.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Group-shared directory | Correct group ownership, directory permissions and setgid where needed. |
| Service denied despite mode bits | Inspect SELinux labels and AVC denials. |
| Permanent label for a custom web path | Define an fcontext rule, then apply restorecon. |
Traps
- Do not solve a labeling error by disabling SELinux.
- chmod 777 does not bypass SELinux and usually grants excessive access.
Active recall
1. Which permission permits traversing a directory?
Execute; reading lists names and writing changes entries.
2. Why use usermod -aG?
To append supplementary membership without dropping other groups.
3. What persists a custom file-context rule?
semanage fcontext followed by restorecon applies a persistent label mapping.
4. Why can a password-locked user still authenticate?
Other credentials such as authorized SSH keys may still be accepted.
5. What must change for a service to use an unusual SELinux-controlled port?
The port’s SELinux type mapping, as well as the service and firewall configuration.