AWS · मराठी आवृत्ती
6.6 CentOS Stream 9: firewalld आणि SELinux
Package commands AL2023 सारखे वाटतील, पण firewalld आणि SELinux चा context वेगळा असू शकतो. दोन्हींची स्थिती तपासा.
Nginx
sudo yum install -y nginx
sudo service nginx start
sudo systemctl enable nginx
sudo service nginx status
sudo nginx -t
curl -I http://localhost
Apache
Nginx stop करून Apache test करा:
sudo yum install -y httpd
sudo service httpd start
sudo systemctl enable httpd
sudo service httpd status
sudo apachectl configtest
curl -I http://localhost # shows the CentOS test page until you add index.html
स्वतःचं index.html नसताना test page दिसू शकतो.
firewalld active असेल तर
sudo systemctl is-active firewalld
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-all
पहिल्या command ने status पाहा. Active असेल तेव्हाच HTTP/HTTPS rules आणि reload करा. Inactive असल्यास ते commands चालतीलच असं नाही; SG आणि इतर host firewall rules तपासा.
SELinux
SELinux mandatory access control देतो. सामान्य enforcing policy मध्ये web processes च्या domain ला योग्य labels असलेलं content वाचता येतं; static content साठी httpd_sys_content_t वापरला जातो.
getenforce # Enforcing / Permissive / Disabled
ls -Z /usr/share/nginx/html /var/www/html # view SELinux labels
sudo restorecon -Rv /var/www/html # fix labels after copying/moving files
sudo setsebool -P httpd_can_network_connect 1 # allow reverse proxy to apps (Node/Flask)
sudo setsebool -P httpd_can_network_connect_db 1 # allow web server/PHP to reach a remote DB
sudo ausearch -m avc -ts recent # see recent SELinux denials (package audit)
getenforce स्थिती, ls -Z labels, restorecon default labels, setsebool निवडक permissions आणि ausearch recent denials दाखवतात. Reverse proxy/remote DB booleans गरज असेल तेवढेच enable करा.
SELinux कायम बंद करून error लपवू नका. Labels/booleans आणि denial logs तपासा. फक्त isolated diagnostic test मध्ये तात्पुरतं permissive करून कारण ओळखलं तर लगेच enforcing परत करा; live security बदल विचारपूर्वक करा.
Lab
getenforce आणि sudo systemctl is-active firewalld नोंदवा. Active असेल तर HTTP allow करा. ls -Z /var/www/html labels तपासा.