Skip to main content
🎤 Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
Back to Blog

SELinux DAC vs MAC Explained

Understand the difference between Discretionary and Mandatory Access Control. Learn why MAC stops attacks that DAC cannot prevent.

Luca BertonMarch 18, 20262 min read

Two Layers of Access Control

Linux has two independent access control systems. Understanding both is essential for securing any production server.

DAC: Discretionary Access Control

DAC is the traditional Unix permission model:

ls -l /etc/passwd
-rw-r--r--. 1 root root 1524 Oct 28 07:13 /etc/passwd

Key characteristics:

  • Based on user identity (uid/gid)
  • Owner controls permissions with chmod, chown
  • Root bypasses most checks
  • Users can share access at their discretion

The problem? If an attacker compromises a process, they inherit all that user's permissions.

Related Course

Master this topic with hands-on labs

Go beyond reading — build real projects in sandboxed environments with expert video guidance.

Browse Courses →

MAC: Mandatory Access Control

MAC adds policy-driven labels that even root must obey:

ls -lZ /etc/passwd
-rw-r--r--. 1 root root system_u:object_r:passwd_file_t:s0 1524 Oct 28 07:13 /etc/passwd

The -Z flag reveals the SELinux security context: system_u:object_r:passwd_file_t:s0.

Key characteristics:

  • Based on labels and policy rules, not identity
  • System policy overrides user decisions
  • Even root is subject to policy constraints
  • Limits damage from compromised processes

The Critical Rule

SELinux can deny access even when DAC allows it. But SELinux cannot allow access when DAC denies it.

They work in layers:

  1. DAC check happens first
  2. If DAC allows, SELinux check happens
  3. Both must allow for access to succeed
Stay Updated

Get weekly IT automation tips

Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.

Subscribe Free →

Security Contexts

Every process and file has a security context with four fields:

user:role:type:level

For example: system_u:system_r:httpd_t:s0

  • User (system_u) — SELinux user identity
  • Role (system_r) — Role-based access control
  • Type (httpd_t) — This is the most important field
  • Level (s0) — MLS sensitivity level

Inspecting Contexts

Use the -Z flag with common commands:

# File contexts
ls -Z /var/www

# Process contexts
ps -eZ | grep httpd

# Your user context
id -Z

Ready to practice DAC vs MAC hands-on? Our SELinux for System Admins course includes real RHEL labs where you'll see both access control layers in action.

---

Ready to go deeper? Check out our hands-on course: SELinux for System Admins — practical exercises you can follow along on your own machine.

Ready to learn by doing?

Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.

Share this article
LB
Luca Berton

Docker Captain, IT automation expert, Red Hat Summit & KubeCon speaker. Building hands-on education for DevOps engineers at CopyPasteLearn.

Related Articles

Explore topics

Browse more articles on the topics covered here.