Supporting Security-Enhanced Linux (SELinux) confinement

Prev Next

Trellix Agent supports all processes to run in SELinux confined mode.

SELinux is a kernel security module that allows enforcement of access controls that are loaded at the start of a system.

You can use SELinux to confine programs and services as well as access to files, network, IPC, and other processes. SELinux RPM provides SELinux policies to confine all services installed by Trellix Agent. When you install Trellix Agent along with SELinux RPM, the SELinux modules create contexts for Trellix Agent processes, binaries, configuration files, log files, etc. and all Agent processes run in SELinux confinement.

Note

Trellix Agent SELinux is supported on RHEL 7.x, 8.x, 9.x, and 10.x versions. Alma Linux version 9.5, 9.6, and 10.0 are supported. For information about the supported versions, see KB-13570.

When you enable Trellix Agent SELinux, the following are the default allowed directories for the processes and features to perform its operations.

  • The command-line, maconfig and cmdagent tools, accesses the directory in /tmp, /var/tmp, /var/log, /var/McAfee/agent/logs.

  • Trellix Agent processes access the directory in /var/McAfee/agent.

  • Super Agent, peer-to-peer and relay accesses the directory in /var/McAfee/agent.

To change the allowed default directory to any other directory when you enable SELinux, you need to perform the steps mentioned in KB94454. For example, you can change the Super Agent or peer-to-peer repository from /var/McAfee/agent to /tests/test through Trellix Agent general policy from ePO - On-prem by following the steps mentioned in KB94454.