Configuring Security Subsystems |
Presence of the SELinux enhanced security subsystem in the OS as well as the use of mandatory access control systems, such as PARSEC—as opposed to the classical discretionary model used by UNIX—causes problems in the work of Dr.Web Server Security Suite when its default settings are used. To ensure correct operation of Dr.Web Server Security Suite in this case, it is necessary to make additional changes to the settings of the security subsystem and/or to the settings of Dr.Web Server Security Suite. This section discusses the following settings that ensure correct operation of Dr.Web Server Security Suite: •configuring SELinux Security Policies, •configuring the launch in the CSE (Closed Software Environment) mode (OS Astra Linux SE 1.6 and 1.7).
This mode has several features. •To run an autonomous copy, you need a valid key file, working in the centralized protection mode is not supported (an option to install the key file, exported from centralized protection server, is available). In this case, even if Dr.Web Server Security Suite is connected to the centralized protection server, the autonomous copy does not notify the centralized protection server of the threats detected in the autonomous copy mode. •All additional components that support the functioning of the autonomous copy, will be launched under the current user and will work with specially generated configuration file. •All temporary files and UNIX sockets are created only in the directory with an unique name, which is created when the autonomous copy is launched. The unique temporary directory is created in the system directory for temporary files (path to this directory is available in the TMPDIR environment variable). •All the required paths to virus databases, the scan engine and executable files used during scanning are defined by default or retrieved from the special environment variables. •The number of the autonomous copies working simultaneously is not limited. •When the autonomous copy is terminated, the set of supporting components also terminates. |