> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/podman/configure-the-selinux-policy-for-powershell-integrations.md).

# Configure the SELinux Policy for PowerShell Integrations

Configure the Podman SELinux policy for PowerShell integrations in Cortex XSOAR 6.14.

The SELinux Policy is a set of rules that guides the SELinux security engine, and defines types for file objects and domains for processes. When running in rootless mode, the default SELinux policy used by Podman may affect processes that mmap **`/dev/zero`**, which may affect running PowerShell integrations.

PowerShell integrations mmap **`/dev/zero`** as part of the .NET Core PInvoke capabilities.

To see whether PowerShell integrations can run in Cortex XSOAR, type the following command:

`!pwsh script="$demisto.results('ok')"`

If the SELinux policy blocks the mapping of `/dev/zero` an error is issued about `OutOfMemoryException`. For example, in the playground, you can see the error:

![podman-error.png](https://content.gitbook.com/content/8xEMUKpU65o1wagTHaO3/blobs/HoCqEeUlOPlNHdO98NbM/d2fdac3cc0796ec751f764d6c0db5dadea6a12af2f4096c79ab112794c32d3b5.png)

You need to configure the policy module and then reset the containers. If you use engines with Podman, you need to apply the policy configuration on each engine machine.

{% hint style="info" %}

### Note

PowerShell integrations use an internal socket which may be blocked by SELinux depending upon the container-selinux version installed. It is recommended to use version 2.144.0 or higher for the container-selinux. To upgrade to the latest container-selinux run the \*\*`sudo yum update container-selinux` \*\*command.
{% endhint %}

1. Fix the SELinux policy by installing the SELinux policy module.
   1. In the Cortex XSOAR Server, create the following file:

      `podman_rootless.te`
   2. Add the following content:

      ```screen
      module podman_rootless 1.0;

      require {
          type zero_device_t;
          type container_t;
          class chr_file execute;
      }

      #============= container_t ==============
      allow container_t zero_device_t:chr_file execute;
      ```
   3. After running a PowerShell integration in Cortex XSOAR, generate the SELinux policy using the `audit2allow` tool by running the following command:

      `sudo grep pwsh /var/log/audit/audit.log | audit2allow -m podman_rootless`
   4. Compile the policy module by running the following commands:
      * `checkmodule -M -m -o podman_rootless.mod podman_rootless.te`
      * `semodule_package -o podman_rootless.pp -m podman_rootless.mod`
   5. Install the policy module by running the following command:

      `sudo semodule -i podman_rootless.pp`
2. Add server configurations and reset the containers in Cortex XSOAR.

   Configure label confinement to allow Python and PowerShell containers to access other script folders.

   1. In Cortex XSOAR Settings → Troubleshooting → Server Configuration, set the following parameters:
      * For Python containers, set python.pass.extra.keys to `--security-opt=label=level:s0:c100,c200`
      * For PowerShell containers, set powershell.pass.extra.keys to `--security-opt=label=level:s0:c100,c200`
   2. In the Cortex XSOAR CLI, run the `/reset_containers` command.
3. Test the PowerShell script by running the following command:

   `!pwsh script="$demisto.results('ok')"`


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/podman/configure-the-selinux-policy-for-powershell-integrations.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
