CHEAT SHEET
SELinux cheat sheet
Modes, contexts, booleans, ports and denials. Fix SELinux problems the right way instead of turning it off.
Modes
getenforce # Enforcing, Permissive or Disabledsestatus # full status and policysetenforce 0 # permissive until the next rebootsetenforce 1 # enforcing again
# /etc/selinux/config (permanent mode, needs a reboot)SELINUX=enforcing
Looking at contexts
ls -Z /var/www/html # contexts of filesps -eZ | grep httpd # contexts of processesid -Z # your own context
A context reads user:role:type:level. The type (for example httpd_sys_content_t) is what the policy checks.
Fixing file contexts
semanage fcontext -a -t httpd_sys_content_t "/web(/.*)?" # define the rule (permanent)restorecon -Rv /web # apply the rule nowsemanage fcontext -l | grep /web # list your ruleschcon -t httpd_sys_content_t /web/index.html # quick change, lost on a relabeltouch /.autorelabel # relabel everything on the next boot
semanage comes from policycoreutils-python-utils. Install it with dnf if the command is missing.
Booleans
getsebool -a | grep httpd # list booleanssetsebool -P httpd_can_network_connect on # change one permanently (-P)semanage boolean -l | grep httpd_can_network_connect # what a boolean does
Ports
semanage port -l | grep http # ports each type may usesemanage port -a -t http_port_t -p tcp 8888 # allow another portsemanage port -d -t http_port_t -p tcp 8888 # remove it again
Troubleshooting denials
ausearch -m AVC -ts recent # recent denialsgrep AVC /var/log/audit/audit.log # raw denialssealert -a /var/log/audit/audit.log # readable analysis (setroubleshoot-server)journalctl -t setroubleshoot # messages from setroubleshoot
Work through it in order: 1) is it enforcing and really SELinux? 2) file context with ls -Z. 3) a boolean. 4) a port. 5) the logs.
Common types
| Type | Used for |
|---|---|
| httpd_sys_content_t | Web content the server reads |
| httpd_sys_rw_content_t | Web content the server may write |
| samba_share_t | Samba shares |
| public_content_t | Read-only content shared by several services |
| container_file_t | Container volumes (use :Z or :z) |
| default_t | Files in a new top-level folder with no rule |
More cheat sheets
Questions
How do I check if SELinux is enforcing?
Run getenforce. It prints Enforcing, Permissive or Disabled. sestatus shows more detail.
How do I fix the SELinux context of a web folder?
Add a rule with semanage fcontext -a -t httpd_sys_content_t "/web(/.*)?", then apply it with restorecon -Rv /web.
How do I let a service use a different port with SELinux?
Use semanage port -a -t http_port_t -p tcp 8888, replacing the type and port with the ones you need.
Should I disable SELinux when something is denied?
No. Check the context, the booleans and the port first. Use setenforce 0 only for a short test, then turn it back on with setenforce 1.