Skip to content
abdallahmekky

CHEAT SHEET

SELinux cheat sheet

Modes, contexts, booleans, ports and denials. Fix SELinux problems the right way instead of turning it off.

All cheat sheets

Modes

getenforce                  # Enforcing, Permissive or Disabledsestatus                    # full status and policysetenforce 0                # permissive until the next rebootsetenforce 1                # enforcing again
# /etc/selinux/config   (permanent mode, needs a reboot)SELINUX=enforcing

Looking at contexts

ls -Z /var/www/html            # contexts of filesps -eZ | grep httpd            # contexts of processesid -Z                          # your own context

A context reads user:role:type:level. The type (for example httpd_sys_content_t) is what the policy checks.

Fixing file contexts

semanage fcontext -a -t httpd_sys_content_t "/web(/.*)?"    # define the rule (permanent)restorecon -Rv /web                                         # apply the rule nowsemanage fcontext -l | grep /web                            # list your ruleschcon -t httpd_sys_content_t /web/index.html                # quick change, lost on a relabeltouch /.autorelabel                                         # relabel everything on the next boot

semanage comes from policycoreutils-python-utils. Install it with dnf if the command is missing.

Booleans

getsebool -a | grep httpd                       # list booleanssetsebool -P httpd_can_network_connect on       # change one permanently (-P)semanage boolean -l | grep httpd_can_network_connect    # what a boolean does

Ports

semanage port -l | grep http                    # ports each type may usesemanage port -a -t http_port_t -p tcp 8888     # allow another portsemanage port -d -t http_port_t -p tcp 8888     # remove it again

Troubleshooting denials

ausearch -m AVC -ts recent                   # recent denialsgrep AVC /var/log/audit/audit.log            # raw denialssealert -a /var/log/audit/audit.log          # readable analysis (setroubleshoot-server)journalctl -t setroubleshoot                 # messages from setroubleshoot

Work through it in order: 1) is it enforcing and really SELinux? 2) file context with ls -Z. 3) a boolean. 4) a port. 5) the logs.

Common types

TypeUsed for
httpd_sys_content_tWeb content the server reads
httpd_sys_rw_content_tWeb content the server may write
samba_share_tSamba shares
public_content_tRead-only content shared by several services
container_file_tContainer volumes (use :Z or :z)
default_tFiles in a new top-level folder with no rule

More cheat sheets

Questions

How do I check if SELinux is enforcing?

Run getenforce. It prints Enforcing, Permissive or Disabled. sestatus shows more detail.

How do I fix the SELinux context of a web folder?

Add a rule with semanage fcontext -a -t httpd_sys_content_t "/web(/.*)?", then apply it with restorecon -Rv /web.

How do I let a service use a different port with SELinux?

Use semanage port -a -t http_port_t -p tcp 8888, replacing the type and port with the ones you need.

Should I disable SELinux when something is denied?

No. Check the context, the booleans and the port first. Use setenforce 0 only for a short test, then turn it back on with setenforce 1.