Labels Drive Everything
In SELinux, labels determine access — not just file permissions. A file with chmod 777 but the wrong SELinux label will still be denied.
Every file has a security context:
ls -Z /var/www
system_u:object_r:httpd_sys_content_t:s0 html
system_u:object_r:httpd_sys_script_exec_t:s0 cgi-binThe type field (httpd_sys_content_t) is what matters most.
The Labeling Problem
Files in non-standard locations inherit the parent directory's label — usually wrong:
mkdir -p /srv/webroot
echo "Hello" > /srv/webroot/index.html
ls -Z /srv/webroot/index.html
unconfined_u:object_r:var_t:s0 /srv/webroot/index.htmlApache needs httpd_sys_content_t but gets var_t. Result: 403 Forbidden.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Quick Fix: chcon
chcon -t httpd_sys_content_t -R /srv/webrootWorks instantly but is not persistent. Use for testing only.
Persistent Fix: semanage + restorecon
Step 1: Check expected context
matchpathcon /srv/webrootStep 2: Define persistent mapping
semanage fcontext -a -t httpd_sys_content_t '/srv/webroot(/.*)?'Step 3: Apply labels
restorecon -Rv /srv/webrootStep 4: Verify
ls -Zd /srv/webroot /srv/webroot/index.htmlGet weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Common Web Labels
| Label | Purpose |
|---|---|
httpd_sys_content_t | Static web content (read-only) |
httpd_sys_rw_content_t | Writable content (uploads) |
httpd_sys_script_exec_t | CGI scripts |
httpd_log_t | Log files |
The Golden Rule
Always use semanage fcontext + restorecon for persistent changes:
matchpathcon— check current expected contextsemanage fcontext -a— define the mappingrestorecon -Rv— apply it- Verify with
ls -Z
Practice this workflow in our SELinux for System Admins course with real RHEL 9/10 labs.
---
Ready to go deeper? Check out our hands-on course: SELinux for System Admins — practical exercises you can follow along on your own machine.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
SELinux Cheat Sheet for RHEL
Quick reference for essential SELinux commands on RHEL 9/10. Modes, contexts, labels, booleans, logs, and troubleshooting in one page.
SELinux Upload Directories Guide
Properly label writable upload directories for Apache with SELinux. Use httpd_sys_rw_content_t to allow writes without disabling security.
SELinux for Apache and PHP-FPM
Configure Apache with PHP-FPM over TCP on RHEL with SELinux enforcing. Diagnose and fix name_connect denials using the correct SELinux boolean and audit tools.
SELinux Policy with sesearch
Use sesearch to query SELinux policy rules. Learn to inspect what httpd_t is allowed to do and verify policy before making changes.
Sigstore Container Image Signing
Sigstore provides keyless signing for container images and software artifacts. Learn how to sign images with Cosign, verify signatures in Kubernetes.
Skupper Multi-Cluster Kubernetes
Skupper connects Kubernetes services across clusters without VPNs or special networking. Learn how to set up multi-cluster communication with Skupper.
Explore topics
Browse more articles on the topics covered here.