温馨提示×

ubuntu selinux怎么迁移

小樊
41
2026-10-01 10:51:14
栏目: 智能运维

在 Ubuntu 上其实默认是不使用 SELinux 的(Ubuntu 默认用的是 AppArmor)。所以“SELinux 迁移”通常有以下几种场景,我先分情况说明,你看看你属于哪一种。


一、Ubuntu 上启用 SELinux(从 AppArmor 迁移到 SELinux)

1. 安装 SELinux

sudo apt update
sudo apt install selinux selinux-utils policycoreutils

2. 修改启动参数

编辑 GRUB:

sudo nano /etc/default/grub

在 GRUB_CMDLINE_LINUX 中加入:

selinux=1 security=selinux

更新 GRUB:

sudo update-grub

3. 禁用 AppArmor(可选但推荐)

sudo systemctl disable apparmor
sudo systemctl stop apparmor

4. 设置 SELinux 模式

先以 permissive 模式启动(只记录不拦截):

sudo setenforce 0

或编辑:

sudo nano /etc/selinux/config

内容:

SELINUX=permissive
SELINUXTYPE=default

5. 重启

sudo reboot

重启后检查:

sestatus

确认无致命错误后,再改为:

SELINUX=enforcing

二、从 CentOS / RHEL 迁移 SELinux 策略到 Ubuntu

⚠️ 不推荐直接复制策略文件,因为发行版差异很大。

正确做法

  1. 在 Ubuntu 上重新安装对应服务的 SELinux 策略
  2. 使用 audit2allow 根据日志生成策略
sudo apt install auditd
sudo ausearch -m avc -ts recent | audit2allow -M mypolicy
sudo semodule -i mypolicy.pp

三、从 SELinux 迁移到 AppArmor(反向迁移)

如果你想回到 Ubuntu 默认安全机制:

sudo apt remove selinux
sudo apt install apparmor apparmor-profiles
sudo systemctl enable apparmor
sudo reboot

四、常见坑(非常重要)

  • Ubuntu 对 SELinux 支持不完整
  • 某些服务(如 snap)与 SELinux 冲突
  • 文件系统需支持 security.selinux 属性(ext4/xfs 通常 OK)
  • 不要在生产环境直接 enforcing

五、建议你补充的信息

为了给你更精确的方案,可以告诉我:

  1. 你现在是 CentOS → Ubuntu 还是 Ubuntu 内部迁移?
  2. 是要迁移 策略 / 配置 / 日志 还是整个安全模型?
  3. 是否是 生产环境?

我可以直接给你一套可执行的迁移步骤。

0 踩