diff options
author | Todd Zullinger <tmz@pobox.com> | 2021-06-07 01:22:26 -0400 |
---|---|---|
committer | Todd Zullinger <tmz@pobox.com> | 2022-01-01 23:45:10 -0500 |
commit | 5337e3d93200e3235a7fddc90d1191187a224a39 (patch) | |
tree | 4b7d6af520b2651121911bdb35cb67682cb2d717 /README.SELinux | |
parent | 8c73716697352a44fb5d4f717ebf01c30ee580ba (diff) | |
download | cgit_EL6-5337e3d93200e3235a7fddc90d1191187a224a39.tar.gz |
update SELinux README
The documentation for SELinux has grown a little stale. Refresh it and
convert it to markdown syntax¹.
Remove outdated data about the graphical system-config-selinux tool.
Mention that restorecon might be needed to update /var/lib/git.
Use the semanage equality option (-e) to simplify the command used to
add an alternate location for git repositories.
¹ The main reason to convert to markdown is to avoid pagure displaying
it as one large blob.
Diffstat (limited to 'README.SELinux')
-rw-r--r-- | README.SELinux | 21 |
1 files changed, 0 insertions, 21 deletions
diff --git a/README.SELinux b/README.SELinux deleted file mode 100644 index 3af6c5a..0000000 --- a/README.SELinux +++ /dev/null @@ -1,21 +0,0 @@ -If you use SELinux, you need to ensure that the httpd_enable_cgi boolean is -set properly. This can be done via the command line, e.g.: - - # setsebool -P httpd_enable_cgi 1 - -Or you can use the graphical tool system-config-selinux, via System -> -Administration -> SELinux Management on the Gnome menu. - -Additionally, the git repositories need to be readable by the cgi. This is -handled automatically for repositories in the default path, /var/lib/git. If -your repositories are in a different path, /srv/git, for example, you can set -the proper context using semanage: - - # semanage fcontext -a -t git_sys_content_t "/srv/git(/.*)?" - -If you have other confined daemons that need to access the git repositories, -you may want to use public_content_t, or public_content_rw_t instead. - -Then use restorecon to update the contexts: - - # restorecon -RF /srv/git |