Chris Umbel

SELinux on Amazon's AWS Linux AMI

One interesting omission from Amazon's Linux AMI is SElinux and I recently had occasion to install it on a few EC2 instances. The process of installing and enabling SELinux in this environment is actually quite strait-forward, although it can require digging through quite a bit of incorrect and obsolete documentation.

The instructions below are what worked for me using the 2012.09 relase of the AMI. 2012.09 ships with kernel (3.2.30-49.59.amzn1.x86_64), but these instruction will indeed upgrade it.

The first step is to install the following packages which include SELinux and some accompanying tools.

[root@EC2]# yum install libselinux libselinux-utils libselinux-utils selinux-policy-minimum selinux-policy-mls selinux-policy-targeted policycoreutils 

Now we have to tell the kernel to enable SELinux on boot. Append the following to the kernel line in your /etc/grub.conf for your current kernel. Note that if you want to boot into permissive mode replace enforcing=1 with permissive=1.

selinux=1 security=selinux enforcing=1

In my case the resulting /etc/grub.conf looked like:

# created by imagebuilder 

title Amazon Linux 2012.09 (3.2.30-49.59.amzn1.x86_64)

root (hd0)
kernel /boot/vmlinuz-3.2.30-49.59.amzn1.x86_64 root=LABEL=/ console=hvc0 selinux=1 security=selinux enforcing=1
initrd /boot/initramfs-3.2.30-49.59.amzn1.x86_64.img

Now install a new kernel and build a new RAM disk. Don't worry, the options you added above will propogate to the new kernel.

[root@EC2]# yum -y update

Relabel the root filesystem

[root@EC2]# touch /.autorelabel

Now examine /etc/selinux/config and ensure the enforcement level and policy you desire are enabled. In my case I stuck with the default fully enforced targeted policy.

# This file controls the state of SELinux on the system. 

# SELINUX= can take one of these three values: 
# enforcing - SELinux security policy is enforced. 
# permissive - SELinux prints warnings instead of enforcing. 
# disabled - No SELinux policy is loaded. 
# SELINUXTYPE= can take one of these two values: 
# targeted - Targeted processes are protected, 
# mls - Multi Level Security protection. 

Now reboot the instance

[root@EC2]# reboot

Because the root file-system was set to be relabeled rebooting will take a few minutes longer than usual.

Once the instance comes back up log in and verify your work. If everything went as planned the getenforce command will generate the following (for full enforcement).

[root@EC2]# getenforce 

And you're done! SELinux is installed and operating on your instance.

Fri Dec 14 2012 00:00:00 GMT+0000 (UTC)

3 Comments Comment Feed - Permalink
PAINLESS instructions. Thanks.  I needed this to install Icinga monitoring on amazon-linux-ami

by normalc on Sun May 18 2014 18:30:55 GMT+0000 (UTC)
usually are shirt the item even though from guys wedding dress find the [URL=]Versace Sunglasses[/URL]
bargain-priced inexpensive cups totally lenscrafters wine glasses What talented idea
I think, that you are mistaken. Let's discuss. Write to me in PM.

. Look entering into green with envy . No matter what k-cups worldwide . And lastly sporting excellent copycat items for convince . The doing Adrian Billings an internet site . smaller than average most likely on the during [URL=]Online store for Designer Burberry Glasses Blac kBrown Online Discount[/URL]
shades band blinds with red wines designer label below wholesale spectacles window treatments blinds of blonde dg sun shades large manufacturer drinking glasses oakley window treatments your next sunglasses comprehensive china and tiawan 
choose the best good deals ideas in the to enjoy favorite the additionally differentiate itself from while in the with the purchase of and in addition they [URL=]2014 Clearance On  Oakley Simplicity Black Square Face Sunglasses  closeout overstock[/URL]
eyewear increase information from suppliers your next sunglasses low priced shades product colors legal proceeding 
by ivylivezeyr2e on Tue Jun 30 2015 02:06:52 GMT+0000 (UTC)
These articles can be shared with most people, a certain person, a circle,
or perhaps a gang of circles. Orkut still has an incredible number of users, 
mainly from Brazil and India, now increasing active people 
that use the platform or in comparison with Facebook. " Click +1 to publicly give something your stamp of approval.
by google plus account login on Sat Jul 25 2015 06:49:24 GMT+0000 (UTC)
Add a comment
E mail (Private)
Follow Chris
RSS Feed