beginner
SELinux for System Admins
Master SELinux on RHEL 9/10. Learn mandatory access control, file contexts, booleans, AVC troubleshooting, and hands-on Apache labs — all with SELinux enforcing.
12 lessons
What it looks like in the lab
sandbox — bash
$ getenforce
Enforcing
$ ls -Z /var/www/html/index.html
system_u:object_r:httpd_sys_content_t:s0 index.html
$ ausearch -m avc -ts recent
type=AVC msg=denied { read } for comm="httpd"
$ setsebool -P httpd_read_user_content on
# Access granted ✓
Real terminal output from the hands-on lab environment
Who this is for
- • Developers moving into DevOps or infrastructure roles
- • System administrators learning modern tooling
- • CS students building practical skills
Lessons
2
DAC vs MAC
3
SELinux Modes and Policy Types
4
Security Contexts and Labels
5
File Context Management
6
semanage and restorecon Workflow
7
AVC Logs and Troubleshooting
8
setroubleshoot and audit2allow
9
SELinux Booleans
10
Lab: Apache Custom Webroot
11
Lab: Apache and PHP-FPM
12
Lab: Upload Directories and Wrap-up
Get started
Start Free LessonFirst lesson is always free — no signup required
12 hands-on lessons
Beginner level
Real Linux sandbox labs
Want all courses?
See Pro plan →