Ravindra Bagale · Cyber Securityसर्व coursesया course चे lessonsशोधाEnglish

Cyber Security · मराठी आवृत्ती

रोजचे management commands आणि SELinux basics

रवींद्र बागले यांच्या course वर आधारित · सहज मराठीत explanation

या page मध्ये

Web-server कामासाठी config test, reload, logs आणि listening ports हे चार भाग नियमित तपासा.

Task Nginx Apache (AL2023/CentOS) Apache (Ubuntu)
Config तपासा sudo nginx -t sudo apachectl configtest sudo apache2ctl configtest
Reload (service/config नुसार कमी disruption) sudo service nginx reload sudo service httpd reload sudo service apache2 reload
Restart sudo service nginx restart sudo service httpd restart sudo service apache2 restart
Error log sudo tail -​f /​var/​log/​nginx/​error.​log sudo tail -​f /​var/​log/​httpd/​error_​log sudo tail -​f /​var/​log/​apache2/​error.​log
Access log /​var/​log/​nginx/​access.​log /​var/​log/​httpd/​access_​log /​var/​log/​apache2/​access.​log
Version nginx -v httpd -v apache2 -v
Modules/build माहिती nginx -V httpd -M apache2ctl -M

Reload करण्याआधी test

sudo nginx -t && sudo service nginx reload मध्ये syntax test यशस्वी झाल्यावरच reload चालतो. त्यामुळे अनेक syntax चुका live config ला लागू होत नाहीत. Test पास झाला म्हणजे सर्व runtime behavior योग्यच असेल अशी हमी नाही; request आणि logs सुद्धा तपासा.

Table मधलं nginx -V version/build options आणि compiled modules बद्दल माहिती देतं; dynamic modules load झालेत का हे active configuration मधूनही तपासा.

SELinux म्हणजे काय?

SELinux हा mandatory access control चा भाग आहे. Process आणि files च्या labels/policy नुसार access ठरतो. httpd_sys_content_t हा read-only web content साठी परिचित type आहे; इतर labels/booleans वेगवेगळ्या गरजांसाठी असतात.

Distribution च्या defaults पेक्षा आपल्या machine चं getenforce output पाहा. Enforcing policy लागू करतो, Permissive denials log करतो पण block करत नाही, Disabled वेगळा state आहे.

getenforce                                  # Enforcing / Permissive / Disabled
ls -Z /usr/share/nginx/html /var/www/html   # view SELinux labels
sudo restorecon -Rv /var/www/html           # fix labels after copying/moving files
sudo setsebool -P httpd_can_network_connect 1      # allow reverse proxy to apps (Node/Flask)
sudo setsebool -P httpd_can_network_connect_db 1   # allow web server/PHP to reach a remote DB
sudo ausearch -m avc -ts recent             # see recent SELinux denials (package audit)

ls -Z labels, restorecon configured defaults प्रमाणे labels restore करतो. Network-connect booleans web process ला app/DB कडे outbound connections साठी permissions देऊ शकतात; फक्त आवश्यक boolean enable करा. ausearch -m avc -ts recent recent denials शोधतो.

Error साठी SELinux बंद करू नका

403/502 दिसल्यास logs, labels आणि policy आधी तपासा. Source मधला sudo setenforce 0 तात्पुरता permissive diagnostic आहे; तो SELinux पूर्ण disable करत नाही पण enforcement कमी करतो. Enforcing lab वर असा diagnostic वापरल्यास नोंद ठेवा आणि sudo setenforce 1 ने पूर्वस्थिती restore करा. Permanent उपाय म्हणजे योग्य label/targeted policy, blanket bypass नाही.

Security मध्ये उपयोग

Web process compromised झाला तरी SELinux policy त्याला कोणत्या files/ports शी काम करता येईल ते मर्यादित करू शकते. म्हणून configuration error दुरुस्त करण्यासाठी हा layer काढून टाकणं योग्य उपाय नाही.

Practice

getenforce आणि ls -Z /var/www/html पाहा. मग Nginx error log live पाहत स्वतःच्या site वर missing page request करा. प्रत्येक missing request error log मध्ये येईलच असं नाही; logging config/access log सुद्धा पाहा.

Chapter recap

आता पुढच्या chapter मध्ये आपली static website host करू.