ç§ãã¡ã®å€ãã¯ãWebãããžã§ã¯ãã®éçšãµãŒããŒã®ã»ããã¢ããã«é¢äžããŠããŸãã ApacheãNginxã®æ§ææ¹æ³ã«ã€ããŠã¯èª¬æããŸãããããã«ã€ããŠã¯ãç§ãããããç¥ã£ãŠããŸãã ãã ããããã³ããšã³ããµãŒããŒãäœæããéã®éèŠãªåŽé¢ã®1ã€ã¯æ¶ç¯ããŠããŸãããããã¯ã»ãã¥ãªãã£ãµãã·ã¹ãã ã®èšå®ã§ãã ãDisable SELinuxãã¯ãã»ãšãã©ã®ã¢ããã¥ã¢ã¬ã€ãã®æšæºçãªæšå¥šäºé ã§ãã ãœããããªã·ãŒã¢ãŒãã§ã»ãã¥ãªãã£ãµãã·ã¹ãã ãèšå®ããããã»ã¹ã¯ãã»ãšãã©ã®å Žåéåžžã«ç°¡åãªã®ã§ãããã¯æ¥ãã§æ±ºå®ããããã«æããŸãã
ä»æ¥ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®Red HatïŒCentOSïŒãã¡ããªã§äœ¿çšãããSELinuxã»ãã¥ãªãã£ãµãã·ã¹ãã ã調æŽããããã€ãã®æ¹æ³ã«ã€ããŠèª¬æããŸãã äŸãšããŠãCentOSããŒãžã§ã³5.8ã§Apache + mod_wsgi + Django + ZEO WebãµãŒããŒã®ãã³ãã«ãæ§æããŸãã
Linuxã»ãã¥ãªãã£ã·ã¹ãã ãæ§æããå Žåãéæã¢ã¯ã»ã¹å¶åŸ¡ïŒDACïŒã·ã¹ãã ã®ãã¬ãŒã ã¯ãŒã¯ã«å¶çŽãããŸãã 3ã€ã®ã¬ãã«ïŒææè ãã°ã«ãŒãææè ãªã©ïŒããã³POSIX ACLã®rwxã®æšæºæš©éãèªç±ã«äœ¿çšã§ããŸãã ãããã£ãŠããŠãŒã¶ãŒæš©éãæã€ã¢ããªã±ãŒã·ã§ã³ã¯ãçè«çã«ã¯ã察å¿ãããŠãŒã¶ãŒãå©çšã§ãããã¹ãŠã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã ã¢ããªã±ãŒã·ã§ã³ãå±éºã«ããããããšãæ²ããçµæãæãå¯èœæ§ããããŸãã
SELinuxïŒSecurity-Enhanced LinuxïŒã¯ãMandatory Access ControlïŒMACïŒãå®è£ ããã»ãã¥ãªãã£ãµãã·ã¹ãã ã§ãããåŸæ¥ã®è£éã·ã¹ãã ãšäžŠè¡ããŠåäœããŸãã ã¢ã¯ã»ã¹æš©ã¯ãããªã·ãŒã䜿çšããŠã·ã¹ãã ã«ãã£ãŠæ±ºå®ãããŸãã ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®Red HatïŒCentOSïŒãã¡ããªã§ã¯ãã«ãŒãã«ã®äžéšãšããŠããã«SELinuxãå ¥æã§ããŸãã ã¿ã¹ã¯ã®æãç°¡åãªãœãªã¥ãŒã·ã§ã³ã«ã¯ãã¿ãŒã²ããããªã·ãŒïŒãã¿ãŒã²ãããïŒãå¿ èŠã§ããããã¯ãäžè¬çãªã¢ããªã±ãŒã·ã§ã³ã®å€§éšåã®ã«ãŒã«ãèšè¿°ããŠããŸãã ç¹å¥ãªåªåãããã«ãåºæ¬çãªãµãŒãã¹ã®åºæ¬çãªä¿è·ãååŸããŸãã ããªã·ãŒã«ãŒã«ã¯ãããã«èšèŒãããŠããªããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ããDACã®ãã¬ãŒã ã¯ãŒã¯ã§SELinuxããã®å¶éãªãã«æ©èœãããããªãã®ã§ãã
ããããããªãå®éã«ãã®SELinuxãå¿ èŠãªã®ã§ããïŒã çãã¯éåžžã«ç°¡åã§ããå Žåã«ãã£ãŠã¯ãã»ãã¥ãªãã£ãµãã·ã¹ãã ã¯å°ãªããšãäžæ£ã¢ã¯ã»ã¹ãèšé²ããããšãèš±å¯ããçæ³çã«ã¯ãããé²ãããšãã§ããŸãã ãããã«ãããéåè ã¯ç¹å®ã®ããã»ã¹ã®ããã«æŠèª¬ããããã¬ãŒã ã¯ãŒã¯å ã§è¡åããå¿ èŠããããŸãã
ç¬èªã®èšå®ãè¿œå ããã«ã¯ãã³ã³ããã¹ãããã¡ã€ã³ãã¢ã¯ã»ã¹ãã¯ãã«ã䜿çšããŠæäœããŸãã ã»ãã¥ãªãã£é¢é£ã®ã€ãã³ãã¯ãã«ãŒãã«ã¬ãã«ã§SELinuxã«ãã£ãŠã€ã³ã¿ãŒã»ãããããŸãã ã»ãã¥ãªãã£ãšã³ãžã³ã®ã¡ã«ããºã ã¯ãDACã«ãŒã«ã®åŸã«æå¹ã«ãªããŸãã SELinuxã¯ãRBACïŒããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ïŒãTEïŒã¿ã€ã匷å¶ïŒãããã³ãªãã·ã§ã³ã§MLSïŒãã«ãã¬ãã«ã»ãã¥ãªãã£ïŒæ©èœãæäŸããŸãã åã·ã¹ãã ãªããžã§ã¯ãã«ã¯ãç¹å®ã®ã³ã³ããã¹ãïŒã¿ã€ãïŒããããŸãã ããªã·ãŒã®ã«ãŒã«ã«åºã¥ããŠãã»ãã¥ãªãã£ãµãã·ã¹ãã ã¯ãã®æäœã®å®è¡ãèš±å¯ãŸãã¯ãããã¯ããããã»ã¹ã¯ãšã©ãŒã¡ãã»ãŒãžãåãåããŸãã SELinuxã«ãã£ãŠè¡ããããã¹ãŠã®æ±ºå®ã¯ãAccess Vector CacheïŒAVCïŒã«ãã£ãã·ã¥ãããŸãã
SELinuxã³ã³ããã¹ãã«ã¯ããŠãŒã¶ãŒãããŒã«ãã¿ã€ããããã³ã¬ãã«ã«é¢ããæ å ±ãå«ãŸããŠããŸãã Type Enforcementã®å±æ§ã§ããã¿ã€ããæäœããŸãã ããã»ã¹ã®ãã¡ã€ã³ãšãã¡ã€ã«ã®ã¿ã€ãã«ãã£ãŠå®çŸ©ãããŸãã SELinuxã«ãŒã«ã¯ãèš±å¯ãããã¿ã€ãã®å¯Ÿè©±ãèšè¿°ããŸãã ã¢ã¯ã»ã¹ã¯ã察å¿ããã«ãŒã«ãããå Žåã«ã®ã¿èš±å¯ãããŸãã
ãããšã¯å¥ã«ããã¡ã€ã³ç§»è¡ã®ãã¯ãããžãŒã«æ³šç®ããããšæããŸãã SELinuxã§ã¯ããœãŒã¹ãã¡ã€ã³ã®ããã»ã¹ããæ°ãããã¡ã€ã³ã®ãšã³ããªãã€ã³ãã¿ã€ãã®ãã¡ã€ã«ããéå§ããã¢ããªã±ãŒã·ã§ã³ãå®è¡ããå Žåãã¢ããªã±ãŒã·ã§ã³ããããã¡ã€ã³ããå¥ã®ãã¡ã€ã³ã«åãæ¿ããããšãã§ããŸãã
æšæºã®ã¿ãŒã²ããããªã·ãŒã¯ã200ãè¶ ããã¢ããªã±ãŒã·ã§ã³ã®ã³ã³ããã¹ãããã¡ã€ã³ãããã³ã¢ã¯ã»ã¹ã«ãŒã«ãäœæããã³èª¬æããŸãã ããªã·ãŒãæ¡åŒµããææ¡ãããã³ã³ããã¹ãã®ãã¬ãŒã ã¯ãŒã¯å ã§è¡åããæ©äŒããããŸãã åºæ¬çãªããªã·ãŒãéçºããéãã»ãšãã©ãã¹ãŠã®äž»èŠãªãŠãŒã¹ã±ãŒã¹ãèæ ®ãããŸããã æšæºãœãªã¥ãŒã·ã§ã³ãäœæããã«ã¯ãå®è³ªçã«äœãå€æŽããå¿ èŠã¯ãããŸããã
ãããã£ãŠããã³ãã¬ãŒããœãªã¥ãŒã·ã§ã³ãå®è£ ããå ŽåãSELinuxä¿è·ã¡ã«ããºã ã®äœ¿çšãæåŠããããšã¯å°ãªããšãæ£åœåãããŸããã è¿œå ã®ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããå Žåããã®äœ¿çšã«ã¯ããã€ãã®å°é£ãçããŸãã ã¿ã¹ã¯ã®ã³ã³ããã¹ãã§ã¯ããããã¯ã¢ãžã¥ãŒã«mod_wsgiãšZEOã§ãã SELinuxã®åäœãç¶æããã«ã¯ãèšå®ãå€æŽããå¿ èŠããããŸãã
ç§ã®äŸã§ã¯ãCentOS 5.8ïŒã«ãŒãã«2.6.18-308.1.1.el5ïŒãšApache WebãµãŒããŒïŒhttpd-2.2.3-63.el5.centos.1ïŒã䜿çšããŠããŸãã PythonïŒ2.7.2ïŒãDjangoïŒ1.4ïŒãmod_wsgiïŒ3.3ïŒãããã³ZopeïŒ3.4.0ïŒãè¿œå ã§ã€ã³ã¹ããŒã«ãããŸãã ïŒãã®ãœãããŠã§ã¢ã®å¹³å¡ãªã€ã³ã¹ããŒã«ããã»ã¹ã¯ãåå¥ã®èª¬æã«å€ããŸãããïŒ
ãŸããhttpdã®SELinuxããªã·ãŒãæ¡åŒµããå¿ èŠããããŸãã ããã©ã«ãèšå®ã¯ãããã»ã¹ã䟵害ãããå Žåã«ããã»ã¹ã確å®ã«åé¢ããããšãç®çãšããŠããŸãã ãã ãããããžã§ã¯ããžã®httpdã¢ã¯ã»ã¹ã«ã¯ãããã€ãã®å€æŽãå¿ èŠã§ãã ããªã·ãŒã®äœæè ã¯ãã³ã³ããã¹ãã«å¶éãå ããŠã¢ããªã±ãŒã·ã§ã³ã®å®å šãªããžãã¯ãäœæããŸããã ç°¡åãªã³ãã³ãã䜿çšãããšãã·ã¹ãã äžã®ãã¡ã€ã«ã®ããŒã¯ã¢ããã«æ £ããã®ã«åœ¹ç«ã¡ãŸãã
semanage fcontext -l | grep httpd
ããªã·ãŒã¯ãæ瀺ãããåã¿ã€ããžã®ã¢ã¯ã»ã¹ã管çããŸãã ã³ã³ããã¹ãã®å®å šãªãªã¹ãã¯ã察å¿ããããã¥ã¢ã«ããŒãžïŒ man httpd_selinux ïŒã«ãããŸãã ããŒã¢ã³ãšã¹ã¯ãªããããã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããhttpd_sys_content_tã¿ã€ãã«èå³ããããŸãã ãããã£ãŠãæšæºã®DACæš©éã«å ããŠããããžã§ã¯ãã®ãã£ã¬ã¯ããªãšãã¡ã€ã«ã®ã³ã³ããã¹ããæå®ããå¿ èŠããããŸãã ããã¯ã chconã³ãã³ãã䜿çšããŠäžåºŠã«å®è¡ã§ããŸãã
chcon -R -t "httpd_sys_content_t" / your /ãããžã§ã¯ã
ãã ããã«ãŒã«ã䜿çšããŠã¿ã€ããèšå®ããããšããå§ãããŸãã ããã«ãããæ°ãããã¡ã€ã«ãè¿œå ãããšãã«åŸç¶ã®èªåã¿ã€ãå²ãåœãŠãä¿èšŒãããŸãã
semanage fcontext -a -t httpd_sys_content_t "/your/project(/.*ïŒïŒ"
restorecon -R / your /ãããžã§ã¯ã
ç§ã®ãã¢ãããžã§ã¯ãã§ã¯ãZoDBããŒã¿ããŒã¹ã§Djangoã䜿çšããŠããŸãã ããŒã¿ããŒã¹ãšã®éä¿¡æ段ãšããŠãZEOã䜿çšãããŸãã ããã¯ã¹ã¿ã³ãã¢ãã³ãœãããŠã§ã¢ã§ãããããSELinuxå ã§æ©èœããããã«ããå¿ èŠããããŸãã åé¢ã確å®ã«ããããã«ã httpd_tãã¡ã€ã³ã®ApacheãŠãŒã¶ãŒæš©éã§ZEOãèµ·åããããšããå§ãããŸãã ãããè¡ãã«ã¯ãããŒã¢ã³ã¢ãŒãã§èµ·åéå§ã¹ã¯ãªãããå®çŸ©ããŸãã ããã§ã¯ãã¹ã¯ãªããã®ãµã€ãºã倧ãããããã¹ã¯ãªããå šäœã®ãªã¹ãã¯æäŸããŸããã äž»ãªãã®ã§ååã§ãã
/ usr / local / bin / zeoctl -d -s / var / run / zeo / zsock -C / etc / zeo / zeoctl.conf start
SELinuxãžã®åŸç¶ã®ã¿ã€ã移è¡äžã®åé¡ãåé¿ããããã«ãåæåã¹ã¯ãªãããé©åãªã³ã³ããã¹ãã«ç§»åããå¿ èŠãããããšãå¿ããªãã§ãã ããã
chcon ât "initrc_exec_t" / etc / init.d / your_init_script
æ§æãã¡ã€ã«ã§ãå¿ èŠãªãŠãŒã¶ãŒãæå®ããå¿ èŠããããŸãã
<ã©ã³ããŒ>
ããã°ã©ã / usr / local / bin / runzeo -a / var / run / zeo / zeo.socket -f / var / your_db_path / db.fs
ããŒã¢ã³ç
ãŠãŒã¶ãŒApache
</ã©ã³ããŒ>
ãœã±ããã¯ãZEOãšDjangoã®éã®ãªã³ã¯ãšããŠäœ¿çšãããŸãã httpdã¯httpd_tãã¡ã€ã³ã§æ©èœãããããã¢ããªã±ãŒã·ã§ã³ãæ¥ç¶ã§ããããã«ãã¿ã€ããšDACæš©éãããŽã·ãšãŒãããå¿ èŠããããŸãã ãããè¡ãã«ã¯ããã£ã¬ã¯ããª/ var / run / zeoãæºåããããã«å¿ èŠãªã³ã³ããã¹ããèšå®ããŸãã -f -sã¹ã€ããã䜿çšããŠã³ã³ããã¹ãã®èªåå²ãåœãŠããœã±ããã®ã¿ã«å¶éãã-f -dã䜿çšããŠã³ã³ããã¹ãããã£ã¬ã¯ããªã«èšå®ããŸãã
semanage fcontext -a -f -d -t 'httpd_sys_script_rw_t' '/var/run/zeo(/.*ïŒïŒ'
semanage fcontext -a -f -s -t 'httpd_sys_script_rw_t' '/var/run/zeo(/.*ïŒïŒ'
restorecon âR / var /å®è¡
ZEOæ§æãã¡ã€ã«ã§ã¯ãéä¿¡ãœã±ããã®åŒ·å¶çãªå Žæãæå®ããå¿ èŠããããŸãã
<ãŒãª>
ã¢ãã¬ã¹/ var / run / zeo / zeo.socket
</ zeo >
ApacheãŠãŒã¶ãŒã®ä»£ããã«ã¢ããªã±ãŒã·ã§ã³ãå®è¡ããäºå®ãªã®ã§ãåã®æšç§»æ§ãèæ ®ããå¿ èŠããããŸãã ã¿ã€ãhttpd_tãååŸããã«ã¯ãå®è¡äžã®ããã»ã¹ãå¿ èŠã§ãã ããã©ã«ãã§ã¯ããã¡ã€ã«/ usr / local / bin / zeoctlããã³/ usr / local / bin / runzeoã«ã¯bin_tã³ã³ããã¹ãããããŸãã ãããã¯unconfined_tãã¡ã€ã³ããåŒã³åºããããããã³ã³ããã¹ãé·ç§»ã®ãã§ãŒã³ããã¬ãŒã¹ããå¿ èŠããããŸãã ãŸãã /etc/init.d/ããã¹ã¯ãªãããåŒã³åºãããŸãããã®ã¹ã¯ãªããã«ã¯ãã¿ã€ãinitrc_exec_tãå²ãåœãŠãããŠããŸãã ãã®ç¶æ³ã®ç§»è¡ãã§ãŒã³ãèŠã€ããŸãã
sesearch -T -s unconfined_t -t initrc_exec_t | grep "initrc_exec_t"
èŠã€ãã£ãé·ç§»ãã§ãŒã³ã¯ã unconfined_t initrc_exec_tïŒããã»ã¹initrc_tã®ããã«èŠããŸã ã ããã»ã¹ãinitrc_tã³ã³ããã¹ããåãåãããšãããããŸãã ãããã£ãŠãä»åºŠã¯å¿ èŠãªã¿ã€ãã®httpd_tã«ã€ãªãã移è¡ãã§ãŒã³ãèŠã€ããå¿ èŠããããŸã ã
sesearch -T -s initrc_t | grep "ããã»ã¹httpd_t"
æ€çŽ¢ã®çµæã¯ã initrc_t httpd_exec_tïŒprocess httpd_t linkã«ãªããŸãã ãã®ç§»è¡ãè¡ãã«ã¯ã httpd_exec_tã³ã³ããã¹ããå®è¡å¯èœãã¡ã€ã«ã«èšå®ããå¿ èŠããããŸãã
semanage fcontext -a -t httpd_exec_t "/ usr / local / bin / zeoctl"
semanage fcontext -a -t httpd_exec_t "/ usr / local / bin / runzeo"
restorecon -R / usr / local / bin
ããã§ãSELinuxããªã·ãŒã®httpdã®ãœã±ããã«ãœã±ããèš±å¯ãè¿œå ããå¿ èŠããããŸãã ãããè¡ãã«ã¯ããã€ãã®æ¹æ³ããããŸãã ãŠãŒã¶ãŒã®èŠ³ç¹ããæãç°¡åãªã®ã¯ãã·ã¹ãã ãã°ããã®AVCã¡ãã»ãŒãžã«åºã¥ããŠããªã·ãŒã¢ãžã¥ãŒã«ãçæã§ããaudit2allowãŠãŒãã£ãªãã£ã§ãã ç¹å®ã®ã¢ã¯ã·ã§ã³ã®èš±å¯ã®ã¿ãäœæããããããŠãŒãã£ãªãã£ã¯æ éã«äœ¿çšããŠãã ãã-ãã ãã 詳现ãªã¬ã€ãã¯éçºè ã®Webãµã€ãã§æäŸãããŠããŸãã
2çªç®ã®æ¹æ³ã¯ãã¢ãžã¥ãŒã«ãæåã§äœæããã³ã³ãã€ã«ããŠãçŸåšã®ããªã·ãŒã«ã€ã³ã¹ããŒã«ããããšã§ãã ãã®æ¹æ³ã«ããããã»ã¹ã®èŠèŠåãåäžããããããã®æ¹æ³ã§ZEOçšã®ã¢ãžã¥ãŒã«ã補é ããŸãã ã¿ã€ãhttpd_sys_script_rw_tã®ãœã±ãããäœæããã³æäœããæš©éãhttpd_tã«ä»äžããŸãã ãããè¡ãã«ã¯ã次ã®å 容ã®ãã¡ã€ã«/tmp/httpdAllowDjangoZEO.teãäœæããŸãã
ã¢ãžã¥ãŒã«httpdAllowDjangoZEO 1.0;
require {
ã¿ã€ãhttpd_t;
ã¿ã€ãhttpd_sys_script_rw_t;
ã¯ã©ã¹sock_fileãªã³ã¯ã
ã¯ã©ã¹sock_file setattr;
class sock_file create;
class sock_file unlink;
class sock_file write;
}
ïŒ============== httpd_t ===============
httpd_tãèš±å¯ããhttpd_sys_script_rw_tïŒsock_fileãªã³ã¯ã
httpd_tãèš±å¯httpd_sys_script_rw_tïŒsock_file setattr;
httpd_tãèš±å¯httpd_sys_script_rw_tïŒsock_file create;
httpd_tãèš±å¯httpd_sys_script_rw_tïŒsock_file unlink;
httpd_tãèš±å¯httpd_sys_script_rw_tïŒsock_file write;
次ã«ãã¢ãžã¥ãŒã«ãäœæããŠã³ã³ãã€ã«ããå¿ èŠããããŸãã ãããè¡ãã«ã¯ã checkmoduleããã³semodule_packageã³ãã³ãã䜿çšããŸã ã çŸåšã®ããªã·ãŒã«ã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããã«ã¯ã semoduleãŠãŒãã£ãªãã£ãå¿ èŠã§ãã
checkmodule -M -m -o / tmp / httpdAllowDjangoZEO.mod / tmp / httpdAllowDjangoZEO.te
semodule_package --outfile / tmp / httpdAllowDjangoZEO.pp --module / tmp / httpdAllowDjangoZEO.mod
semodule -i httpdAllowDjangoZEO.pp
æåŸã®ã¢ã¯ã·ã§ã³ã¯ãZoDBããŒã¿ããŒã¹ã®ä¿ç®¡å Žæã®ã³ã³ããã¹ããšZEOæ§æãã¡ã€ã«ãæ§æããããšã§ãã ãã®éçšã§ãæè¡çãª.lockãã¡ã€ã«ãäœæããå¿ èŠããããŸãã ãããã£ãŠãããŒã¿ããŒã¹ã®ä¿åå Žæã¯ããã¡ã€ã«ã®äœæãèš±å¯ããé©åãªã³ã³ããã¹ãã§ããŒã¯ããå¿ èŠããããŸãã ã Httpd_sys_script_rw_t ãã¯ããã«é©ããŠããŸãã
semanage fcontext âa âtâ httpd_sys_script_rw_tââ / var / your_db_path ïŒ /ã* ïŒ ïŒâ
æ§æãã¡ã€ã«ã«ã¯ç¹æ®ãªã¿ã€ããhttpd_config_tãããããŸãã
semanage fcontext âa âtâ httpd_config_tââ / etc / zeo ïŒ /ã* ïŒ ïŒâ
次ã«ããµãŒãã¹ãåèµ·åããŠãæ§æããã»ã¹ãå®äºããŸãã
åŒç€Ÿãäœæããã«ãŒã«ã«ããããã³ãã«å šäœãåé¡ãªãæ©èœããŸãã åæã«ããµãŒããŒãšãã®ãµãŒãã¹ã«è¿œå ã®SELinuxä¿è·ãæäŸããŸãã DjangoãŸãã¯ZEOã³ã³ããŒãã³ãã®ããããã䟵害ãããå Žåãæ»æè ã¯httpd_tãã¡ã€ã³å ã§è¡åãããããå¶éãããã·ã¹ãã ã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã
ãã®ãããSELinuxãç¡å¹ã«ããããšãªããhttpdã®ãŠãŒã¶ãŒèšå®ãæ©èœãããããšãã§ããŸããã åæ§ã«ãã¢ããªã±ãŒã·ã§ã³ã®èŠå¶ããªã·ãŒãäœæã§ããŸãã ããã«ã¯æéãããããŸããããæ·±å»ãªçè«çãã¬ãŒãã³ã°ãå¿ èŠãããŸããã ãããã£ãŠãSELinuxãç¡å¹ã«ããªãã§ãã ããã
SELinuxãã¯ãããžãŒãããå æ¬çã«ç解ããããã«ãFedora 13çšã®SELinuxã®ãã·ã¢èªã®èª¬æãããç解ããããšããå§ãããŸãã