Skip to content

Getting Started with SELinux

Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x

SELinux (Security-Enhanced Linux) is the mandatory access control (MAC) system enabled by default on EL systems. Many newcomers to EL encounter their first “mysterious issues” related to SELinux.

  • What SELinux is and why you should not disable it
  • The three operating modes and their differences
  • How to view and troubleshoot SELinux denials
  • Common SELinux management commands
  • A system running EL 9.x
  • sudo privileges
  • policycoreutils and setroubleshoot-server installed (usually pre-installed)

SELinux effectively reduces the impact of security vulnerabilities by restricting processes to only access resources permitted by their policies. Even if a service is compromised, the attacker can only access resources that the service is authorized to use.

ModeDescriptionEnforces Policy
EnforcingEnforces policy, denies unauthorized accessYes
PermissiveDoes not block, but logs violationsNo (logging only)
DisabledCompletely turned offNo
Check current mode
$ getenforce
Enforcing
Check detailed status
$ sestatus
Temporarily switch to Permissive (reverts after reboot)
$ sudo setenforce 0
Temporarily switch back to Enforcing
$ sudo setenforce 1

When SELinux denies an operation, it records an AVC (Access Vector Cache) message in the audit log.

  1. View recent denial records

    Use ausearch to view AVC denials
    $ sudo ausearch -m avc -ts recent
  2. Use sealert for human-readable recommendations

    Install setroubleshoot (if not already installed)
    $ sudo dnf install -y setroubleshoot-server
    Analyze the log and provide fix recommendations
    $ sudo sealert -a /var/log/audit/audit.log | head -50
  3. Apply the recommended fixes

    sealert typically provides specific fix commands, such as setting the correct file context or enabling a boolean.

Terminal window
$ ls -Z /var/www/html/
Restore default contexts
$ sudo restorecon -Rv /var/www/html/
View all httpd-related booleans
$ getsebool -a | grep httpd
Allow httpd to make network connections
$ sudo setsebool -P httpd_can_network_connect on

The SELinux context of the files may be incorrect:

Terminal window
$ sudo semanage fcontext -a -t httpd_sys_content_t "/data/www(/.*)?"
$ sudo restorecon -Rv /data/www/

Service Cannot Bind to a Non-Standard Port

Section titled “Service Cannot Bind to a Non-Standard Port”
View ports allowed for httpd
$ sudo semanage port -l | grep http_port_t
Add an allowed port
$ sudo semanage port -a -t http_port_t -p tcp 8443

SELinux policy on EL 10 continues to be updated, with overall usage compatible with EL 9. However, there is one important related change:

Crypto policy: SHA-1 disabled by default

EL 10’s default crypto policy (DEFAULT) disables SHA-1 signature algorithms, affecting:

  • Old SSH RSA keys (1024-bit) signed with SHA-1 will be rejected
  • SSL/TLS certificates issued with SHA-1 will fail validation
  • Some older GPG signatures

If you encounter connection rejections, check the current crypto policy:

Check current system crypto policy
update-crypto-policies --show
Temporarily allow SHA-1 (not recommended for production)
sudo update-crypto-policies --set DEFAULT:SHA1

The recommended approach is to switch to Ed25519 or RSA-4096 keys rather than lowering the security policy.