Skip to main content
🎤 Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
beginner

SELinux for System Admins

Master SELinux on RHEL 9/10. Learn mandatory access control, file contexts, booleans, AVC troubleshooting, and hands-on Apache labs — all with SELinux enforcing.

12 lessons

What it looks like in the lab

sandbox — bash
$ getenforce
Enforcing
$ ls -Z /var/www/html/index.html
system_u:object_r:httpd_sys_content_t:s0 index.html
$ ausearch -m avc -ts recent
type=AVC msg=denied { read } for comm="httpd"
$ setsebool -P httpd_read_user_content on
# Access granted ✓

Real terminal output from the hands-on lab environment

Who this is for

  • • Developers moving into DevOps or infrastructure roles
  • • System administrators learning modern tooling
  • • CS students building practical skills

Lessons

2
DAC vs MAC
3
SELinux Modes and Policy Types
4
Security Contexts and Labels
5
File Context Management
6
semanage and restorecon Workflow
7
AVC Logs and Troubleshooting
8
setroubleshoot and audit2allow
9
SELinux Booleans
10
Lab: Apache Custom Webroot
11
Lab: Apache and PHP-FPM
12
Lab: Upload Directories and Wrap-up

Get started

Start Free Lesson

First lesson is always free — no signup required

12 hands-on lessons
Beginner level
Real Linux sandbox labs

Want all courses?

See Pro plan →