Skip to main content
🎤 Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
Back to Blog

SELinux Policy with sesearch

Use sesearch to query SELinux policy rules. Learn to inspect what httpd_t is allowed to do and verify policy before making changes.

Luca BertonMarch 23, 20261 min read

Why Query the Policy?

When troubleshooting SELinux, you need to know what's supposed to work. sesearch queries the active policy to answer questions like:

  • Can Apache read httpd_sys_content_t files?
  • Can Apache make outbound TCP connections?

Installing setools

dnf install setools-console
Related Course

Master this topic with hands-on labs

Go beyond reading — build real projects in sandboxed environments with expert video guidance.

Browse Courses →

Basic Usage

All allow rules for a domain

sesearch --allow -s httpd_t

Check a specific interaction

sesearch --allow -s httpd_t -t httpd_sys_content_t -c file -p read

Returns a rule = allowed. Empty = denied.

Check network permissions

sesearch --allow -s httpd_t -c tcp_socket -p name_connect

Connecting to AVC Troubleshooting

AVC denial says httpd_t denied getattr on var_t:

sesearch --allow -s httpd_t -t var_t -c file -p getattr

Empty — no rule. Compare with correct label:

sesearch --allow -s httpd_t -t httpd_sys_content_t -c file -p getattr

Returns a rule — confirming the fix is relabeling.

Stay Updated

Get weekly IT automation tips

Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.

Subscribe Free →

Policy Source vs Active Policy

On RHEL, the active policy is compiled. You don't edit .te files directly. Use sesearch to query and audit2allow to generate local modules when needed.

The Investigation Pattern

  1. Read the AVC → note source type, target type, class, permission
  2. Query with sesearch → confirm no rule exists
  3. Query the correct target type → confirm the rule exists
  4. Fix the label or enable the boolean

Learn to investigate policy in our SELinux for System Admins course.

---

Ready to go deeper? Check out our hands-on course: SELinux for System Admins — practical exercises you can follow along on your own machine.

Ready to learn by doing?

Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.

Share this article
LB
Luca Berton

Docker Captain, IT automation expert, Red Hat Summit & KubeCon speaker. Building hands-on education for DevOps engineers at CopyPasteLearn.

Related Articles

Explore topics

Browse more articles on the topics covered here.