Why Query the Policy?
When troubleshooting SELinux, you need to know what's supposed to work. sesearch queries the active policy to answer questions like:
- Can Apache read
httpd_sys_content_tfiles? - Can Apache make outbound TCP connections?
Installing setools
dnf install setools-consoleMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Basic Usage
All allow rules for a domain
sesearch --allow -s httpd_tCheck a specific interaction
sesearch --allow -s httpd_t -t httpd_sys_content_t -c file -p readReturns a rule = allowed. Empty = denied.
Check network permissions
sesearch --allow -s httpd_t -c tcp_socket -p name_connectConnecting to AVC Troubleshooting
AVC denial says httpd_t denied getattr on var_t:
sesearch --allow -s httpd_t -t var_t -c file -p getattrEmpty — no rule. Compare with correct label:
sesearch --allow -s httpd_t -t httpd_sys_content_t -c file -p getattrReturns a rule — confirming the fix is relabeling.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Policy Source vs Active Policy
On RHEL, the active policy is compiled. You don't edit .te files directly. Use sesearch to query and audit2allow to generate local modules when needed.
The Investigation Pattern
- Read the AVC → note source type, target type, class, permission
- Query with
sesearch→ confirm no rule exists - Query the correct target type → confirm the rule exists
- Fix the label or enable the boolean
Learn to investigate policy in our SELinux for System Admins course.
---
Ready to go deeper? Check out our hands-on course: SELinux for System Admins — practical exercises you can follow along on your own machine.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
SELinux Cheat Sheet for RHEL
Quick reference for essential SELinux commands on RHEL 9/10. Modes, contexts, labels, booleans, logs, and troubleshooting in one page.
SELinux Upload Directories Guide
Properly label writable upload directories for Apache with SELinux. Use httpd_sys_rw_content_t to allow writes without disabling security.
SELinux for Apache and PHP-FPM
Configure Apache with PHP-FPM over TCP on RHEL with SELinux enforcing. Diagnose and fix name_connect denials using the correct SELinux boolean and audit tools.
Sigstore Container Image Signing
Sigstore provides keyless signing for container images and software artifacts. Learn how to sign images with Cosign, verify signatures in Kubernetes.
Skupper Multi-Cluster Kubernetes
Skupper connects Kubernetes services across clusters without VPNs or special networking. Learn how to set up multi-cluster communication with Skupper.
Snyk Developer Security Platform
Snyk finds and fixes vulnerabilities in code, dependencies, containers, and infrastructure as code. Learn how to integrate Snyk into your development workflow.
Explore topics
Browse more articles on the topics covered here.