Getting Started with SELinux
Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x
SELinux (Security-Enhanced Linux) is the mandatory access control (MAC) system enabled by default on EL systems. Many newcomers to EL encounter their first “mysterious issues” related to SELinux.
What You Will Learn
Section titled “What You Will Learn”- What SELinux is and why you should not disable it
- The three operating modes and their differences
- How to view and troubleshoot SELinux denials
- Common SELinux management commands
Prerequisites
Section titled “Prerequisites”- A system running EL 9.x
- sudo privileges
policycoreutilsandsetroubleshoot-serverinstalled (usually pre-installed)
Why You Should Not Disable SELinux
Section titled “Why You Should Not Disable SELinux”SELinux effectively reduces the impact of security vulnerabilities by restricting processes to only access resources permitted by their policies. Even if a service is compromised, the attacker can only access resources that the service is authorized to use.
Three Operating Modes
Section titled “Three Operating Modes”| Mode | Description | Enforces Policy |
|---|---|---|
| Enforcing | Enforces policy, denies unauthorized access | Yes |
| Permissive | Does not block, but logs violations | No (logging only) |
| Disabled | Completely turned off | No |
$ getenforceEnforcing$ sestatusTemporarily Switching Modes
Section titled “Temporarily Switching Modes”$ sudo setenforce 0$ sudo setenforce 1Troubleshooting SELinux Denials
Section titled “Troubleshooting SELinux Denials”When SELinux denies an operation, it records an AVC (Access Vector Cache) message in the audit log.
-
View recent denial records
Use ausearch to view AVC denials $ sudo ausearch -m avc -ts recent -
Use sealert for human-readable recommendations
Install setroubleshoot (if not already installed) $ sudo dnf install -y setroubleshoot-serverAnalyze the log and provide fix recommendations $ sudo sealert -a /var/log/audit/audit.log | head -50 -
Apply the recommended fixes
sealerttypically provides specific fix commands, such as setting the correct file context or enabling a boolean.
Common Management Operations
Section titled “Common Management Operations”View SELinux Context of Files
Section titled “View SELinux Context of Files”$ ls -Z /var/www/html/Restore File Contexts
Section titled “Restore File Contexts”$ sudo restorecon -Rv /var/www/html/View and Set Booleans
Section titled “View and Set Booleans”$ getsebool -a | grep httpd$ sudo setsebool -P httpd_can_network_connect onCommon Issues
Section titled “Common Issues”Nginx/Apache Cannot Access Files
Section titled “Nginx/Apache Cannot Access Files”The SELinux context of the files may be incorrect:
$ sudo semanage fcontext -a -t httpd_sys_content_t "/data/www(/.*)?"$ sudo restorecon -Rv /data/www/Service Cannot Bind to a Non-Standard Port
Section titled “Service Cannot Bind to a Non-Standard Port”$ sudo semanage port -l | grep http_port_t$ sudo semanage port -a -t http_port_t -p tcp 8443Further Reading
Section titled “Further Reading”- SSH Hardening
- Firewalld Advanced
man selinux/man sealert
EL 10 Notes
Section titled “EL 10 Notes”SELinux policy on EL 10 continues to be updated, with overall usage compatible with EL 9. However, there is one important related change:
Crypto policy: SHA-1 disabled by default
EL 10’s default crypto policy (DEFAULT) disables SHA-1 signature algorithms, affecting:
- Old SSH RSA keys (1024-bit) signed with SHA-1 will be rejected
- SSL/TLS certificates issued with SHA-1 will fail validation
- Some older GPG signatures
If you encounter connection rejections, check the current crypto policy:
update-crypto-policies --showsudo update-crypto-policies --set DEFAULT:SHA1The recommended approach is to switch to Ed25519 or RSA-4096 keys rather than lowering the security policy.