Two Layers of Access Control
Linux has two independent access control systems. Understanding both is essential for securing any production server.
DAC: Discretionary Access Control
DAC is the traditional Unix permission model:
ls -l /etc/passwd
-rw-r--r--. 1 root root 1524 Oct 28 07:13 /etc/passwdKey characteristics:
- Based on user identity (uid/gid)
- Owner controls permissions with
chmod,chown - Root bypasses most checks
- Users can share access at their discretion
The problem? If an attacker compromises a process, they inherit all that user's permissions.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →MAC: Mandatory Access Control
MAC adds policy-driven labels that even root must obey:
ls -lZ /etc/passwd
-rw-r--r--. 1 root root system_u:object_r:passwd_file_t:s0 1524 Oct 28 07:13 /etc/passwdThe -Z flag reveals the SELinux security context: system_u:object_r:passwd_file_t:s0.
Key characteristics:
- Based on labels and policy rules, not identity
- System policy overrides user decisions
- Even root is subject to policy constraints
- Limits damage from compromised processes
The Critical Rule
SELinux can deny access even when DAC allows it. But SELinux cannot allow access when DAC denies it.
They work in layers:
- DAC check happens first
- If DAC allows, SELinux check happens
- Both must allow for access to succeed
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Security Contexts
Every process and file has a security context with four fields:
user:role:type:levelFor example: system_u:system_r:httpd_t:s0
- User (
system_u) — SELinux user identity - Role (
system_r) — Role-based access control - Type (
httpd_t) — This is the most important field - Level (
s0) — MLS sensitivity level
Inspecting Contexts
Use the -Z flag with common commands:
# File contexts
ls -Z /var/www
# Process contexts
ps -eZ | grep httpd
# Your user context
id -ZReady to practice DAC vs MAC hands-on? Our SELinux for System Admins course includes real RHEL labs where you'll see both access control layers in action.
---
Ready to go deeper? Check out our hands-on course: SELinux for System Admins — practical exercises you can follow along on your own machine.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
What Is SELinux and Why It Matters
SELinux enforces mandatory access control on Linux. Learn what it is, why 87% of enterprises need it, and how it stops real attacks like Log4Shell.
SELinux Cheat Sheet for RHEL
Quick reference for essential SELinux commands on RHEL 9/10. Modes, contexts, labels, booleans, logs, and troubleshooting in one page.
SELinux Upload Directories Guide
Properly label writable upload directories for Apache with SELinux. Use httpd_sys_rw_content_t to allow writes without disabling security.
SELinux File Contexts and Labels
Master SELinux file labeling with semanage fcontext and restorecon. The persistent labeling workflow every sysadmin needs to know.
SELinux Policy with sesearch
Use sesearch to query SELinux policy rules. Learn to inspect what httpd_t is allowed to do and verify policy before making changes.
Sigstore Container Image Signing
Sigstore provides keyless signing for container images and software artifacts. Learn how to sign images with Cosign, verify signatures in Kubernetes.
Explore topics
Browse more articles on the topics covered here.