The Problem
You move Apache's DocumentRoot to /srv/webroot. Permissions are fine, config is valid. But:
curl http://localhost/index.html
# 403 ForbiddenMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Why It Happens
Files under /var/www are labeled httpd_sys_content_t. Custom paths get var_t:
matchpathcon /srv/webroot /var/www
/srv/webroot system_u:object_r:var_t:s0
/var/www system_u:object_r:httpd_sys_content_t:s0Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Step-by-Step Fix
1. Create the webroot
mkdir -p /srv/webroot
echo "SELinux Test" > /srv/webroot/index.html2. Configure Apache
DocumentRoot "/srv/webroot"
<Directory "/srv/webroot">
AllowOverride None
Require all granted
</Directory>3. Quick test with chcon
chcon -t httpd_sys_content_t -R /srv/webroot
curl http://localhost/index.html
# SELinux Test4. Make it permanent
semanage fcontext -a -t httpd_sys_content_t '/srv/webroot(/.*)?'
restorecon -Rv /srv/webroot5. Verify new files inherit correctly
touch /srv/webroot/newfile.html
ls -Z /srv/webroot/newfile.html
# httpd_sys_content_tThe Complete Workflow
matchpathcon— discover the expected labelsemanage fcontext -a— define the persistent mappingrestorecon -Rv— apply labels from policy- Verify with
ls -Z
Build muscle memory for this in our SELinux for System Admins course.
---
Ready to go deeper? Check out our hands-on course: SELinux for System Admins — practical exercises you can follow along on your own machine.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
SELinux for Apache and PHP-FPM
Configure Apache with PHP-FPM over TCP on RHEL with SELinux enforcing. Diagnose and fix name_connect denials using the correct SELinux boolean and audit tools.
SELinux Upload Directories Guide
Properly label writable upload directories for Apache with SELinux. Use httpd_sys_rw_content_t to allow writes without disabling security.
SELinux Cheat Sheet for RHEL
Quick reference for essential SELinux commands on RHEL 9/10. Modes, contexts, labels, booleans, logs, and troubleshooting in one page.
Flux GitOps Kubernetes Tutorial
Flux is a GitOps tool that continuously reconciles your Kubernetes cluster with a Git repository. Learn how to set up Flux, manage Helm releases, and handle.
Flux GitOps Toolkit Deep Dive
Flux v2 uses GitOps Toolkit controllers for source management, Kustomize, Helm, and notifications. Learn how to structure a Flux GitOps repository.
Getting Started with Docker
Learn Docker fundamentals from scratch — containers, images, Dockerfiles, and real-world workflows. No prior experience needed.
Explore topics
Browse more articles on the topics covered here.