{"id":4679,"date":"2022-12-20T18:36:46","date_gmt":"2022-12-20T21:36:46","guid":{"rendered":"http:\/\/lode.uno\/linux-man\/index.php\/2022\/12\/20\/service_seusers-man5\/"},"modified":"2022-12-20T18:36:46","modified_gmt":"2022-12-20T21:36:46","slug":"service_seusers-man5","status":"publish","type":"post","link":"https:\/\/lode.uno\/linux-man\/2022\/12\/20\/service_seusers-man5\/","title":{"rendered":"service_seusers (man5)"},"content":{"rendered":"<h1 align=\"center\">service_seusers<\/h1>\n<p> <a href=\"#NAME\">NAME<\/a><br \/> <a href=\"#DESCRIPTION\">DESCRIPTION<\/a><br \/> <a href=\"#FILE FORMAT\">FILE FORMAT<\/a><br \/> <a href=\"#EXAMPLES\">EXAMPLES<\/a><br \/> <a href=\"#SEE ALSO\">SEE ALSO<\/a> <\/p>\n<hr>\n<h2>NAME <a name=\"NAME\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\">service_seusers \u2212 The SELinux GNU\/Linux user and service to SELinux user mapping configuration files<\/p>\n<h2>DESCRIPTION <a name=\"DESCRIPTION\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\">These are optional files that allow services to define an SELinux user when authenticating via SELinux-aware login applications such as <b>PAM<\/b>(8).<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\">There is one file for each GNU\/Linux user name that will be required to run a service with a specific SELinux user name.<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\">The path for each configuration file is formed by the path returned by <b>selinux_policy_root<\/b>(3) with <i>\/logins\/username<\/i> appended (where <i>username<\/i> is a file representing the GNU\/Linux user name). The default services directory is located at:<\/p>\n<p style=\"margin-left:22%;\"><i>\/etc\/selinux\/{SELINUXTYPE}\/logins<\/i><\/p>\n<p style=\"margin-left:11%; margin-top: 1em\">Where <i>{SELINUXTYPE}<\/i> is the entry from the selinux configuration file <i>config<\/i> (see <b>selinux_config<\/b>(5)).<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>getseuser<\/b>(3) reads this file to map services to an SELinux user.<\/p>\n<h2>FILE FORMAT <a name=\"FILE FORMAT\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\">Each line within the <i>username<\/i> file is formatted as follows with each component separated by a colon:<\/p>\n<p style=\"margin-left:22%;\"><i>service<\/i><b>:<\/b><i>seuser<\/i>[<b>:<\/b><i>range<\/i>]<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\">Where:<\/p>\n<p style=\"margin-left:22%;\"><i>service<\/i><\/p>\n<p style=\"margin-left:32%;\">The service name used by the application.<\/p>\n<p style=\"margin-left:22%;\"><i>seuser<\/i><\/p>\n<p style=\"margin-left:32%;\">The SELinux user name.<\/p>\n<p style=\"margin-left:22%;\"><i>range<\/i><\/p>\n<p style=\"margin-left:32%;\">The range for MCS\/MLS policies.<\/p>\n<h2>EXAMPLES <a name=\"EXAMPLES\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\">Example 1 &#8211; for the \u2019root\u2019 user:<\/p>\n<p style=\"margin-left:22%;\"># .\/logins\/root <br \/> ipa:user_u:s0 <br \/> this_service:unconfined_u:s0<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\">Example 2 &#8211; for GNU\/Linux user \u2019rch\u2019:<\/p>\n<p style=\"margin-left:22%;\"># .\/logins\/rch <br \/> ipa:unconfined_u:s0 <br \/> that_service:unconfined_u:s0<\/p>\n<h2>SEE ALSO <a name=\"SEE ALSO\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>selinux<\/b>(8), <b>PAM<\/b>(8), <b>selinux_policy_root<\/b>(3), <b>getseuser<\/b>(3), <b>selinux_config<\/b>(5)<\/p>\n<hr>\n","protected":false},"excerpt":{"rendered":"<p>  service_seusers \u2212 The SELinux GNU\/Linux user and service to SELinux user mapping configuration files <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[959],"tags":[961,1291,1608],"class_list":["post-4679","post","type-post","status-publish","format-standard","hentry","category-5-formatos-de-ficheros","tag-961","tag-man5","tag-service_seusers"],"gutentor_comment":0,"_links":{"self":[{"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/posts\/4679","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/comments?post=4679"}],"version-history":[{"count":0,"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/posts\/4679\/revisions"}],"wp:attachment":[{"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/media?parent=4679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/categories?post=4679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/tags?post=4679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}