1
00:00:06,510 --> 00:00:07,860
- In this lesson 18.4,

2
00:00:08,700 --> 00:00:12,990
we're gonna talk about
Group Policy and SELinux.

3
00:00:12,990 --> 00:00:14,220
In the Windows environment,

4
00:00:14,220 --> 00:00:16,530
we can use Windows Group policy.

5
00:00:16,530 --> 00:00:19,320
Windows Group Policy provides
a centralized management

6
00:00:19,320 --> 00:00:22,320
and configuration of
our operating systems,

7
00:00:22,320 --> 00:00:25,230
our applications, our user settings,

8
00:00:25,230 --> 00:00:26,460
that are all part of the

9
00:00:26,460 --> 00:00:29,313
Microsoft Windows Active
Directory environment.

10
00:00:30,570 --> 00:00:33,330
Now, a GPO or a Group Policy object

11
00:00:33,330 --> 00:00:35,190
is a group of settings.

12
00:00:35,190 --> 00:00:38,700
And GPOs can be associated with a single

13
00:00:38,700 --> 00:00:41,430
or numerous active directory containers

14
00:00:41,430 --> 00:00:43,980
including sites, domains,

15
00:00:43,980 --> 00:00:47,040
and OU's or organizational units.

16
00:00:47,040 --> 00:00:51,240
Now we use the group Policy
Management Console, GPMC,

17
00:00:51,240 --> 00:00:54,930
which is a snap-in to provide
a single administrative tool

18
00:00:54,930 --> 00:00:58,410
for managing Group Policy
across the enterprise.

19
00:00:58,410 --> 00:01:01,440
So we're gonna talk very high
level about Group Policy,

20
00:01:01,440 --> 00:01:04,140
specifically what some of the
security enhancements are,

21
00:01:04,140 --> 00:01:09,140
because literally we could do
40 hours, 80 hours, 120 hours

22
00:01:09,309 --> 00:01:12,840
just on Windows networking
and Group Policy.

23
00:01:12,840 --> 00:01:15,603
So think of this as a
really high level survey.

24
00:01:17,100 --> 00:01:20,133
So let's look at some Group
Policy Security Enhancements.

25
00:01:21,343 --> 00:01:23,760
Account policies, user
rights, audit policies,

26
00:01:23,760 --> 00:01:26,280
our Windows firewall, our
software restrictions,

27
00:01:26,280 --> 00:01:29,430
our Windows update, having Command Prompt,

28
00:01:29,430 --> 00:01:32,673
and PowerShell, and
disallowing Removable Media.

29
00:01:33,750 --> 00:01:37,170
Our account policies allow
us to specify password

30
00:01:37,170 --> 00:01:40,650
account lockout and Kerberos settings.

31
00:01:40,650 --> 00:01:43,380
Our user rights allow
us to specify the users

32
00:01:43,380 --> 00:01:46,620
or groups that have rights
or privileges on a device.

33
00:01:46,620 --> 00:01:49,830
Our audit policies specify
our security settings

34
00:01:49,830 --> 00:01:52,290
that can control the
logging of security events

35
00:01:52,290 --> 00:01:54,900
and we know how important logging is.

36
00:01:54,900 --> 00:01:57,780
Our Windows firewall
specifies settings and rules

37
00:01:57,780 --> 00:02:00,333
for local Windows stateful firewalls.

38
00:02:01,530 --> 00:02:04,440
Our software restrictions
specify settings to identify

39
00:02:04,440 --> 00:02:08,910
and control software
installation and execution.

40
00:02:08,910 --> 00:02:11,880
Our Windows update settings
control how Windows updates

41
00:02:11,880 --> 00:02:13,780
are going to be installed on a device.

42
00:02:14,790 --> 00:02:17,040
Command and PowerShell options control

43
00:02:17,040 --> 00:02:19,050
how we moderate access to

44
00:02:19,050 --> 00:02:22,290
either a command prompt or to PowerShell.

45
00:02:22,290 --> 00:02:24,660
We can use GPOs to disallow access

46
00:02:24,660 --> 00:02:26,610
to removable media drives,

47
00:02:26,610 --> 00:02:31,170
including DVDs, CDs and
well, even floppy drives.

48
00:02:31,170 --> 00:02:34,800
So again, this is just a really,
really high level overview.

49
00:02:34,800 --> 00:02:35,633
You know, Microsoft Active directory

50
00:02:35,633 --> 00:02:40,633
and Group Policy have just
incredible, incredible myriad

51
00:02:40,890 --> 00:02:44,190
of security options and enhancements.

52
00:02:44,190 --> 00:02:47,010
But all I'm doing here to you
today is just introducing you

53
00:02:47,010 --> 00:02:50,883
to the idea of Group Policy
and Group Policy objects.

54
00:02:52,200 --> 00:02:54,030
Similarly, at a high level,

55
00:02:54,030 --> 00:02:58,020
let's look at security
enhanced Linux or SELinux.

56
00:02:58,020 --> 00:03:00,780
Now SELinux, Security Enhanced Linux

57
00:03:00,780 --> 00:03:04,410
is a Linux kernel access
control security module.

58
00:03:04,410 --> 00:03:05,550
Now it was created by the

59
00:03:05,550 --> 00:03:09,720
United States National Security
Agency, NSA and Red Hat.

60
00:03:09,720 --> 00:03:12,120
But the security module is available

61
00:03:12,120 --> 00:03:15,030
for most Linux distros or distributions

62
00:03:15,030 --> 00:03:18,900
but it's mainly used on RHEL and Fedora.

63
00:03:18,900 --> 00:03:22,740
Now SELinux operates on the
principle of lease privilege.

64
00:03:22,740 --> 00:03:26,130
And by default, everything is denied,

65
00:03:26,130 --> 00:03:28,860
and that a policy is written
that gives each element

66
00:03:28,860 --> 00:03:32,550
of the system a process,
a user, and so on,

67
00:03:32,550 --> 00:03:35,250
only the permissions that
it needs to function.

68
00:03:35,250 --> 00:03:37,860
'Cause remember the
idea of least-privilege

69
00:03:37,860 --> 00:03:39,480
which we're only going to give the rights

70
00:03:39,480 --> 00:03:42,210
and the permissions and
the privileges necessary

71
00:03:42,210 --> 00:03:43,260
to accomplish a task.

72
00:03:43,260 --> 00:03:44,880
We are not going to give our user

73
00:03:44,880 --> 00:03:47,193
or subject anything more
than what they need.

74
00:03:48,720 --> 00:03:51,600
So we have SELinux security policies.

75
00:03:51,600 --> 00:03:54,030
SELinux security policies
are a set of rules

76
00:03:54,030 --> 00:03:57,060
that instruct SELinux users who has access

77
00:03:57,060 --> 00:03:58,620
to the system resources.

78
00:03:58,620 --> 00:04:00,480
Now, there are two types of policies.

79
00:04:00,480 --> 00:04:03,210
A targeted policy and a strict policy.

80
00:04:03,210 --> 00:04:06,210
A targeted policy, which is
really the most common one

81
00:04:06,210 --> 00:04:09,540
is where only selected
processes are protected.

82
00:04:09,540 --> 00:04:11,970
A strict policy is more stringent where

83
00:04:11,970 --> 00:04:13,923
all processes are protected.

84
00:04:16,080 --> 00:04:17,550
Now, SELinux uses what's known

85
00:04:17,550 --> 00:04:19,860
as role-based access control.

86
00:04:19,860 --> 00:04:22,110
Role-based access
control is gonna be a way

87
00:04:22,110 --> 00:04:25,680
of grouping privileges and
assigning them to users.

88
00:04:25,680 --> 00:04:27,510
So access control is going to be based

89
00:04:27,510 --> 00:04:30,923
on the user-role-type model.

90
00:04:32,390 --> 00:04:34,117
An SELinux user is used
in the security context

91
00:04:35,876 --> 00:04:39,720
and the Linux user is gonna
be mapped to an SELinux user.

92
00:04:39,720 --> 00:04:41,880
So we'll have your regular
Linux user account,

93
00:04:41,880 --> 00:04:44,043
and you'll be mapped to an SELinux user.

94
00:04:45,434 --> 00:04:48,780
Now, the SELinux users are
going to be assigned to roles

95
00:04:48,780 --> 00:04:50,910
and those roles determine
what the user can do

96
00:04:50,910 --> 00:04:51,783
in the system.

97
00:04:53,155 --> 00:04:55,020
Now, types are associated with processes

98
00:04:55,020 --> 00:04:58,080
and resources like files or devices.

99
00:04:58,080 --> 00:05:00,390
A role can be associated
with multiple types,

100
00:05:00,390 --> 00:05:04,540
and these associations
will dictate what types

101
00:05:04,540 --> 00:05:09,303
a user's processes can transition
to based upon their roles.

102
00:05:10,477 --> 00:05:13,230
Now, there are three SELinux modes,

103
00:05:13,230 --> 00:05:16,470
enforcing, permissive, and disabled.

104
00:05:16,470 --> 00:05:20,340
Enforcing mode is a default
in most secure SELinux mode.

105
00:05:20,340 --> 00:05:24,360
In this mode, SELinux enforces
the access control policies

106
00:05:24,360 --> 00:05:27,510
and does not allow users to override them.

107
00:05:27,510 --> 00:05:29,910
In permissive mode, the SELinux

108
00:05:29,910 --> 00:05:32,070
does not enforce the policies

109
00:05:32,070 --> 00:05:35,610
but logs events when a
user or process attempts to

110
00:05:35,610 --> 00:05:38,640
access a resource that is
blocked off by the policies.

111
00:05:38,640 --> 00:05:43,050
And this really allows us to
monitor for potential issues.

112
00:05:43,050 --> 00:05:44,550
And then we have disabled mode.

113
00:05:44,550 --> 00:05:47,700
In disabled mode, SELinux does not enforce

114
00:05:47,700 --> 00:05:49,170
the access control policy

115
00:05:49,170 --> 00:05:52,230
and this mode is really
more useful for debugging

116
00:05:52,230 --> 00:05:54,750
or when we're just really
trying to learn more

117
00:05:54,750 --> 00:05:57,750
about how to set up these configurations.

118
00:05:57,750 --> 00:05:59,580
So just having a basic understanding

119
00:05:59,580 --> 00:06:01,500
of GPO's Group Policy objects

120
00:06:01,500 --> 00:06:04,110
in Microsoft Windows Active directory,

121
00:06:04,110 --> 00:06:06,780
and then SELinux is gonna be important

122
00:06:06,780 --> 00:06:08,550
for your examination.

123
00:06:08,550 --> 00:06:11,133
And that takes us to a
three second challenge.

124
00:06:13,170 --> 00:06:14,550
Question one.

125
00:06:14,550 --> 00:06:16,350
Microsoft Windows Active Directory

126
00:06:16,350 --> 00:06:18,603
centralized management approach.

127
00:06:20,010 --> 00:06:21,993
One, two, three.

128
00:06:23,670 --> 00:06:25,120
That's gonna be Group Policy.

129
00:06:26,070 --> 00:06:27,090
Number two.

130
00:06:27,090 --> 00:06:29,583
A collection of Group Policy settings.

131
00:06:30,780 --> 00:06:32,643
One, two, three.

132
00:06:33,660 --> 00:06:36,603
That's gonna be a GPO or
a Group Policy Object.

133
00:06:37,470 --> 00:06:38,820
Number three.

134
00:06:38,820 --> 00:06:40,600
The Linux kernel access control

135
00:06:41,774 --> 00:06:44,520
security module that
was created by the NSA.

136
00:06:44,520 --> 00:06:46,710
One, two, three.

137
00:06:46,710 --> 00:06:48,093
That's SELinux.

138
00:06:49,320 --> 00:06:50,460
Number four.

139
00:06:50,460 --> 00:06:51,900
The principle of giving subjects

140
00:06:51,900 --> 00:06:53,703
minimal rights and permissions.

141
00:06:54,630 --> 00:06:56,253
One, two, three.

142
00:06:57,270 --> 00:06:59,640
That's gonna be least privilege.

143
00:06:59,640 --> 00:07:01,350
And lastly, number five.

144
00:07:01,350 --> 00:07:05,460
The default and most secure SELinux mode.

145
00:07:05,460 --> 00:07:07,680
One, two, three.

146
00:07:07,680 --> 00:07:10,560
And that's gonna be enforcing mode.

147
00:07:10,560 --> 00:07:11,901
How'd you do?

148
00:07:11,901 --> 00:07:13,500
I hope you did great.

149
00:07:13,500 --> 00:07:16,830
So let's do a security-in-action
about Linux Security.

150
00:07:16,830 --> 00:07:18,390
Apply your knowledge.

151
00:07:18,390 --> 00:07:21,030
Your organization recently
installed an Apache web

152
00:07:21,030 --> 00:07:24,150
server running a Linux operating system.

153
00:07:24,150 --> 00:07:26,640
Now there is a need for
strict access controls

154
00:07:26,640 --> 00:07:28,140
over certain directories,

155
00:07:28,140 --> 00:07:29,970
and you've been asked if this is

156
00:07:29,970 --> 00:07:32,010
an appropriate use of SELinux.

157
00:07:32,010 --> 00:07:33,480
So how do you respond?

158
00:07:33,480 --> 00:07:35,160
So as our recap, right?

159
00:07:35,160 --> 00:07:37,470
You have this Apache Web server

160
00:07:37,470 --> 00:07:40,140
it's running a Linux operating system.

161
00:07:40,140 --> 00:07:42,660
There's a need to have
strict access control

162
00:07:42,660 --> 00:07:44,490
over certain directories.

163
00:07:44,490 --> 00:07:48,360
And the question is,
does SELinux make sense?

164
00:07:48,360 --> 00:07:49,890
Go ahead and put me on pause.

165
00:07:49,890 --> 00:07:52,240
Think about this for a
minute and come on back.

166
00:07:53,490 --> 00:07:54,450
Absolutely.

167
00:07:54,450 --> 00:07:55,710
This would be an appropriate use

168
00:07:55,710 --> 00:07:58,050
of SELinux access control

169
00:07:58,050 --> 00:08:01,803
using a targeted policy in enforcing mode.

170
00:08:02,640 --> 00:08:05,550
Now, the caveat being that SELinux can be

171
00:08:05,550 --> 00:08:07,800
complex to configure and manage,

172
00:08:07,800 --> 00:08:10,830
and the initial implementation
mode should probably

173
00:08:10,830 --> 00:08:15,333
be permissive to ensure that
it is implemented correctly.

174
00:08:16,590 --> 00:08:20,340
Now, SELinux is just part of
a defense in depth strategy.

175
00:08:20,340 --> 00:08:22,890
And should be used right alongside

176
00:08:22,890 --> 00:08:25,020
other security measures.

177
00:08:25,020 --> 00:08:27,390
Doing that, well, you
know what it is, right?

178
00:08:27,390 --> 00:08:29,103
It is security in action.

179
00:08:30,210 --> 00:08:31,230
There's your word cloud.

180
00:08:31,230 --> 00:08:32,340
You know what to do.

181
00:08:32,340 --> 00:08:34,953
When you're ready, head
on over to our next quiz.
