Mode Management
getenforce
setenforce 0 # permissive (temp)
setenforce 1 # enforcing (temp)
vi /etc/sysconfig/selinux # permanentInspecting Contexts
ls -Z /var/www # file contexts
ps -eZ | grep httpd # process contexts
id -Z # user contextFile Labeling
Temporary
chcon -t httpd_sys_content_t -R /srv/webrootPersistent
semanage fcontext -a -t httpd_sys_content_t '/srv/webroot(/.*)?'
restorecon -Rv /srv/webroot
matchpathcon /srv/webrootMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Common Web Labels
| Label | Use |
|---|---|
httpd_sys_content_t | Read-only web content |
httpd_sys_rw_content_t | Writable (uploads, cache) |
httpd_sys_script_exec_t | CGI scripts |
Booleans
getsebool -a | grep httpd
setsebool -P httpd_can_network_connect on| Boolean | Purpose |
|---|---|
httpd_can_network_connect | Outbound TCP |
httpd_can_network_connect_db | Database connections |
httpd_enable_homedirs | Serve home dirs |
httpd_can_sendmail | Send emails |
Troubleshooting
grep AVC /var/log/audit/audit.log
ausearch -m AVC,USER_AVC -ts recent
journalctl -t setroubleshoot
grep AVC /var/log/audit/audit.log | audit2allowGet weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Policy Inspection
dnf install setools-console
sesearch --allow -s httpd_t -t httpd_sys_content_t -c file -p readRequired Packages
dnf install policycoreutils policycoreutils-python-utils setools-console setroubleshoot-serverWorkflow
getenforce— confirm models -Z/ps -eZ— check contextsausearch -m AVC -ts recent— find denials- Fix: relabel or boolean
- Custom policy only as last resort
Mistakes to Avoid
chconwithoutsemanage(temporary!)- Blind
audit2allow -Mwithout reviewing.te setenforce 0and forgetting- Disabling SELinux entirely
- Labeling entire webroots as
rw
Bookmark this and practice in our SELinux for System Admins course.
---
Ready to go deeper? Check out our hands-on course: SELinux for System Admins — practical exercises you can follow along on your own machine.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
SELinux DAC vs MAC Explained
Understand the difference between Discretionary and Mandatory Access Control. Learn why MAC stops attacks that DAC cannot prevent.
What Is SELinux and Why It Matters
SELinux enforces mandatory access control on Linux. Learn what it is, why 87% of enterprises need it, and how it stops real attacks like Log4Shell.
SELinux Upload Directories Guide
Properly label writable upload directories for Apache with SELinux. Use httpd_sys_rw_content_t to allow writes without disabling security.
SELinux File Contexts and Labels
Master SELinux file labeling with semanage fcontext and restorecon. The persistent labeling workflow every sysadmin needs to know.
SELinux Policy with sesearch
Use sesearch to query SELinux policy rules. Learn to inspect what httpd_t is allowed to do and verify policy before making changes.
Sigstore Container Image Signing
Sigstore provides keyless signing for container images and software artifacts. Learn how to sign images with Cosign, verify signatures in Kubernetes.
Explore topics
Browse more articles on the topics covered here.