{"id":5759,"date":"2024-11-09T19:17:25","date_gmt":"2024-11-09T10:17:25","guid":{"rendered":"https:\/\/hobby.mydns.jp\/teruki.wp\/?p=5759"},"modified":"2024-11-09T19:17:25","modified_gmt":"2024-11-09T10:17:25","slug":"post-5759","status":"publish","type":"post","link":"https:\/\/hobby.mydns.jp\/teruki.wp\/2024\/11\/09\/post-5759\/","title":{"rendered":"SELinux\u306b\u3088\u308aWordPress\u306e\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u304c\u3067\u304d\u306a\u3044"},"content":{"rendered":"<p>\u30d7\u30e9\u30b0\u30a4\u30f3\u306e\u66f4\u65b0\u3084\u3001Wordpress\u306e\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u304c\u3067\u304d\u306a\u304b\u3063\u305f\u3002\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u304c\u4f5c\u6210\u3067\u304d\u306a\u3044\u3068\u3044\u3046\u30e1\u30c3\u30bb\u30fc\u30b8\u3060\u3063\u305f\u3002<br \/>\n\u30c7\u30a3\u30ec\u30af\u30c8\u30eawordpress\/wp-content\u306e\u30d1\u30fc\u30df\u30c3\u30b7\u30e7\u30f3\u306e\u8a31\u53ef\u3092\u5909\u66f4\u3057\u305f\u308a\u3057\u3066\u307f\u305f\u3051\u3069\u3001\u72b6\u6cc1\u306f\u5909\u308f\u3089\u306a\u304b\u3063\u305f\u3002<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-5760\" src=\"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-content\/uploads\/2024\/11\/\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8-2.png\" alt=\"\" width=\"745\" height=\"286\" srcset=\"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-content\/uploads\/2024\/11\/\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8-2.png 745w, https:\/\/hobby.mydns.jp\/teruki.wp\/wp-content\/uploads\/2024\/11\/\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8-2-300x115.png 300w, https:\/\/hobby.mydns.jp\/teruki.wp\/wp-content\/uploads\/2024\/11\/\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8-2-530x203.png 530w, https:\/\/hobby.mydns.jp\/teruki.wp\/wp-content\/uploads\/2024\/11\/\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8-2-565x217.png 565w, https:\/\/hobby.mydns.jp\/teruki.wp\/wp-content\/uploads\/2024\/11\/\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8-2-710x273.png 710w, https:\/\/hobby.mydns.jp\/teruki.wp\/wp-content\/uploads\/2024\/11\/\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8-2-725x278.png 725w\" sizes=\"auto, (max-width: 745px) 100vw, 745px\" \/><\/p>\n<p>%&gt;sudo setenforce 0\u3000\u3067SELinux\u3092\u7121\u52b9\u306b\u3057\u305f\u3089\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3067\u304d\u305f\u3002<br \/>\n%&gt;sudo setenforce 1\u3000\u3067SELinux\u3092\u6709\u52b9\u306b\u623b\u3057\u305f\u3089\u4e0a\u56f3\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u304c\u307e\u305f\u51fa\u305f\u3002<\/p>\n<p>\u3069\u3046\u3084\u3089\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u304chttpd_sys_content_t\u3060\u3063\u305f\u306e\u304c\u539f\u56e0\u306e\u3088\u3046\u3002httpd_sys<span style=\"color: #ff0000;\">_<strong>rw<\/strong>_<\/span>content_t\u306b\u5909\u66f4\u304c\u5fc5\u8981\u3060\u3063\u305f\u3002\u6b21\u306e\u3088\u3046\u306b\u3057\u3066\u8ffd\u52a0\u3057\u305f\u3002<\/p>\n<pre>%&gt;sudo semanage fcontext -a -t httpd_sys_rw_content_t \"wordpress\u30c7\u30a3\u30ec\u30af\u30c8\u30ea(\/.*)?\"\r\n%&gt;sudo semanage fcontext -l | grep wordpress\r\nwordpress\u30c7\u30a3\u30ec\u30af\u30c8\u30ea(\/.*)?           all files          system_u:object_r:httpd_sys_rw_content_t:s0\r\n%&gt;\r\n%&gt;restorecon -v -R wordpress\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\r\n%&gt;\r\n%&gt;less \/etc\/selinux\/targeted\/contexts\/files\/file_contexts.local\r\nwordpress\u30c7\u30a3\u30ec\u30af\u30c8\u30ea(\/.*)?           all files          system_u:object_r:httpd_sys_rw_content_t:s0\r\n%&gt;\r\n<\/pre>\n<p>\u5909\u66f4\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3067\u304d\u305f\u3002<\/p>\n<pre>[almalinux9 ~\/public_html\/wordpress]$ ls -lZ\r\ndrwxr-xrwx.  6 apache apache unconfined_u:object_r:httpd_sys<span style=\"color: #ff0000;\">_rw_<\/span>content_t:s0   127 Oct 23 16:08 wp-content\/\r\n\u30fb\u30fb\u30fb\r\n<\/pre>\n<p>\u3042\u3068\u3001SELinux\u304c\u539f\u56e0\u3060\u3068\u308f\u304b\u308b\u524d\u306b\u3001\u3044\u308d\u3044\u308d\u3044\u3058\u3063\u3066\u3044\u3066\u3001\u30b5\u30fc\u30d0\u30fc\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u3068\u901a\u4fe1\u304c\u30d6\u30ed\u30c3\u30af\u3055\u308c\u3066\u3001Access Denied\u306b\u306a\u308b\u5834\u5408\u306b\u4ee5\u4e0b\u306e\u8a2d\u5b9a\u3082\u5fc5\u8981\u3068\u3044\u3046\u60c5\u5831\u304c\u3042\u3063\u305f\u306e\u3067\u5ff5\u306e\u305f\u3081\u306b\u8a2d\u5b9a\u3057\u3066\u304a\u3044\u305f\u3002\u3053\u308c\u307e\u3067\u3001Access Denied\u306b\u306a\u308b\u3053\u3068\u306f\u7121\u304b\u3063\u305f\u306e\u3067\u3001\u3044\u3058\u308b\u5fc5\u8981\u306f\u306a\u304b\u3063\u305f\u306e\u304b\u3082\u3057\u308c\u306a\u3044\u3002<\/p>\n<pre>[almalinux9 ~\/public_html\/wordpress\/wp-content]$ getsebool -a | grep httpd | sort\r\nhttpd_anon_write --&gt; off\r\nhttpd_builtin_scripting --&gt; on\r\nhttpd_can_check_spam --&gt; off\r\nhttpd_can_connect_ftp --&gt; off\r\nhttpd_can_connect_ldap --&gt; off\r\nhttpd_can_connect_mythtv --&gt; off\r\nhttpd_can_connect_zabbix --&gt; off\r\nhttpd_can_manage_courier_spool --&gt; off\r\nhttpd_can_network_connect --&gt; on\r\nhttpd_can_network_connect_cobbler --&gt; off\r\nhttpd_can_network_connect_db --&gt; <strong><span style=\"color: #ff0000;\">off<\/span><\/strong>\r\nhttpd_can_network_memcache --&gt; off\r\nhttpd_can_network_relay --&gt; off\r\nhttpd_can_sendmail --&gt; off\r\n\r\n[almalinux9 ~\/public_html\/wordpress\/wp-content]$ sudo setsebool -P <span style=\"color: #ff0000;\">httpd_can_network_connect_db<\/span> <strong><span style=\"color: #ff0000;\">1<\/span><\/strong>\r\n[almalinux9 ~\/public_html\/wordpress\/wp-content]$ getsebool -a | grep httpd | sort\r\nhttpd_can_network_connect --&gt; on\r\nhttpd_can_network_connect_cobbler --&gt; off\r\nhttpd_can_network_connect_db --&gt; <strong><span style=\"color: #ff0000;\">on\r\n\r\n<\/span><\/strong><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u30d7\u30e9\u30b0\u30a4\u30f3\u306e\u66f4\u65b0\u3084\u3001Wordpress\u306e\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u304c\u3067\u304d\u306a\u304b\u3063\u305f\u3002\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u304c\u4f5c\u6210\u3067\u304d\u306a\u3044\u3068\u3044\u3046\u30e1\u30c3\u30bb\u30fc\u30b8\u3060\u3063\u305f\u3002 \u30c7\u30a3\u30ec\u30af\u30c8\u30eawordpress\/wp-content\u306e\u30d1\u30fc\u30df\u30c3\u30b7\u30e7\u30f3\u306e\u8a31\u53ef\u3092\u5909\u66f4\u3057\u305f\u308a\u3057\u3066\u307f\u305f\u3051\u3069\u3001 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":5760,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":["post-5759","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-unix"],"_links":{"self":[{"href":"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-json\/wp\/v2\/posts\/5759","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-json\/wp\/v2\/comments?post=5759"}],"version-history":[{"count":1,"href":"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-json\/wp\/v2\/posts\/5759\/revisions"}],"predecessor-version":[{"id":5761,"href":"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-json\/wp\/v2\/posts\/5759\/revisions\/5761"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-json\/wp\/v2\/media\/5760"}],"wp:attachment":[{"href":"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-json\/wp\/v2\/media?parent=5759"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-json\/wp\/v2\/categories?post=5759"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hobby.mydns.jp\/teruki.wp\/wp-json\/wp\/v2\/tags?post=5759"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}