Digi Control документация

Digi Control документация

Security, integrity и safe repair

SELinux, permissions, checksums, trust, capabilities и drift.

Какво обхваща

  • Security view обединява SELinux mode/contexts, permission baseline, module integrity, runtime-state checksums, trust, capabilities и access policy.
  • Permission baseline показва expected owner/group/mode и drift; safe repair е allow-listed и supports dry-run.
  • Important state се writes atomically и има checksums; damaged state се preserves for recovery, не empty overwrite.
  • Module integrity проверява manifest, files, services/binaries и trust.

Как се работи

  1. Run audit/dry-run.
  2. Review exact drift.
  3. Apply safe repair.
  4. Re-evaluate integrity.
  5. Review audit.

Важни правила

  • Не disable-вайте SELinux като universal fix.
  • Admin не bypass-ва confirmations/locks/source policy.
  • Integrity failure може да hide/block module.