Skip to main content
🎤 Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
Back to Blog

SELinux Cheat Sheet for RHEL

Quick reference for essential SELinux commands on RHEL 9/10. Modes, contexts, labels, booleans, logs, and troubleshooting in one page.

Luca BertonMarch 26, 20261 min read

Mode Management

getenforce
setenforce 0          # permissive (temp)
setenforce 1          # enforcing (temp)
vi /etc/sysconfig/selinux  # permanent

Inspecting Contexts

ls -Z /var/www        # file contexts
ps -eZ | grep httpd   # process contexts
id -Z                 # user context

File Labeling

Temporary

chcon -t httpd_sys_content_t -R /srv/webroot

Persistent

semanage fcontext -a -t httpd_sys_content_t '/srv/webroot(/.*)?'
restorecon -Rv /srv/webroot
matchpathcon /srv/webroot
Related Course

Master this topic with hands-on labs

Go beyond reading — build real projects in sandboxed environments with expert video guidance.

Browse Courses →

Common Web Labels

LabelUse
httpd_sys_content_tRead-only web content
httpd_sys_rw_content_tWritable (uploads, cache)
httpd_sys_script_exec_tCGI scripts

Booleans

getsebool -a | grep httpd
setsebool -P httpd_can_network_connect on
BooleanPurpose
httpd_can_network_connectOutbound TCP
httpd_can_network_connect_dbDatabase connections
httpd_enable_homedirsServe home dirs
httpd_can_sendmailSend emails

Troubleshooting

grep AVC /var/log/audit/audit.log
ausearch -m AVC,USER_AVC -ts recent
journalctl -t setroubleshoot
grep AVC /var/log/audit/audit.log | audit2allow
Stay Updated

Get weekly IT automation tips

Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.

Subscribe Free →

Policy Inspection

dnf install setools-console
sesearch --allow -s httpd_t -t httpd_sys_content_t -c file -p read

Required Packages

dnf install policycoreutils policycoreutils-python-utils setools-console setroubleshoot-server

Workflow

  1. getenforce — confirm mode
  2. ls -Z / ps -eZ — check contexts
  3. ausearch -m AVC -ts recent — find denials
  4. Fix: relabel or boolean
  5. Custom policy only as last resort

Mistakes to Avoid

  • chcon without semanage (temporary!)
  • Blind audit2allow -M without reviewing .te
  • setenforce 0 and forgetting
  • Disabling SELinux entirely
  • Labeling entire webroots as rw

Bookmark this and practice in our SELinux for System Admins course.

---

Ready to go deeper? Check out our hands-on course: SELinux for System Admins — practical exercises you can follow along on your own machine.

Ready to learn by doing?

Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.

Share this article
LB
Luca Berton

Docker Captain, IT automation expert, Red Hat Summit & KubeCon speaker. Building hands-on education for DevOps engineers at CopyPasteLearn.

Related Articles

Explore topics

Browse more articles on the topics covered here.