The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Read current mode | getenforce | View examples |
| Inspect SELinux status | sestatus | View examples |
| Show file contexts | ls -ldZ /srv/reporting /srv/reporting/index.html | View examples |
| Show process domains | ps -eZ | grep '[h]ttpd' | View examples |
| Find recent denials | sudo ausearch -m \
AVC,USER_AVC,SELINUX_ERR,USER_SELINUX_ERR -ts recent | View examples |
| Analyze audit log | sudo sealert -a /var/log/audit/audit.log | View examples |
| Compare expected label | matchpathcon -V /srv/reporting/index.html | View examples |
| Add persistent mapping | sudo semanage fcontext -a -t httpd_sys_content_t \
'/srv/reporting(/.*)?' | View examples |
| Apply expected labels | sudo restorecon -Rv /srv/reporting | View examples |
| Remove local mapping | sudo semanage fcontext -d '/srv/reporting(/.*)?' | View examples |
| Inspect service booleans | getsebool -a | grep '^httpd_' | View examples |
| Change boolean temporarily | sudo setsebool httpd_can_network_connect on | View examples |
| Persist a boolean | sudo setsebool -P httpd_can_network_connect on | View examples |
| Inspect allowed ports | sudo semanage port -l | grep '^http_port_t' | View examples |
| Authorize a custom port | sudo semanage port -a -t http_port_t -p tcp 8443 | View examples |
| Set system permissive temporarily | sudo setenforce 0 | View examples |
| Persist a permissive domain | sudo semanage permissive -a httpd_t | View examples |
| Re-enforce a domain | sudo semanage permissive -d httpd_t | View examples |
| Search allow rules | sesearch -A -s httpd_t -t httpd_sys_content_t -c file -p \
read | View examples |
| List policy modules | sudo semodule -lfull | View examples |
SELinux adds mandatory access control after ordinary user, group, and mode checks. Treat a denial as evidence to investigate, not as a reason to disable enforcement: establish the process domain and target type, reproduce one known request, inspect the correlated audit event, and prefer a documented boolean, port type, or persistent file-context mapping. Record and review every local policy change, test its rollback, and keep the host enforcing whenever possible.
Step by step
Detailed examples
Establish runtime and persistent posture before troubleshooting
getenforce reports the running mode, while sestatus also exposes the policy and configured mode. Enforcing denies disallowed operations; permissive continues them while logging AVC decisions. Disabled neither enforces nor reliably labels newly created objects. A setenforce change is temporary, whereas SELINUX= in /etc/selinux/config affects later boots. Do not move a production host to permissive merely to make an application start.
getenforce
sestatus
grep '^SELINUX=' /etc/selinux/config Confirm discretionary access and both sides of the SELinux decision
SELinux evaluates a source process context against a target object context, object class, and requested permission after normal DAC checks. Record the service domain, exact target label, ownership, modes, and mount behavior. A service running unconfined or under an unexpected domain is a deployment problem; a file carrying default_t or an unrelated service type is usually a labeling problem, not evidence that a new allow rule is needed.
ps -eZ | grep '[h]ttpd'
ls -ldZ /srv/reporting /srv/reporting/index.html
namei -om /srv/reporting/index.html Correlate one reproduced request with its complete AVC event
Reproduce a known request once, note its timestamp, and query AVC, USER_AVC, and SELinux error records. Read the source context, target context, object class, and denied permission together; adjacent SYSCALL and PATH records may supply the executable and path. If Audit is unavailable, inspect the kernel journal. sealert can summarize evidence, but its proposal is not an authorization decision. Never install an audit2allow-generated module without understanding each rule.
sudo ausearch -m AVC,USER_AVC,SELINUX_ERR,USER_SELINUX_ERR -ts recent
sudo journalctl -t setroubleshoot --since '15 minutes ago' --no-pager
sudo sealert -a /var/log/audit/audit.log Fix non-standard paths in the file-context database, then relabel
chcon changes only the current extended attribute and can be undone by restorecon or a full relabel. For an intentional non-standard location, add a narrowly anchored semanage fcontext expression, review it, and apply it with restorecon. The mapping is persistent; restorecon changes current labels. Rollback is also two-stage: delete the exact local mapping, then use restorecon to apply whatever default mapping now wins. Test the expression against a staging path before a recursive production relabel.
sudo semanage fcontext -a -t httpd_sys_content_t '/srv/reporting(/.*)?'
sudo semanage fcontext -l -C | grep '/srv/reporting'
matchpathcon /srv/reporting/index.html
sudo restorecon -Rv /srv/reporting
matchpathcon -V /srv/reporting/index.html Use documented policy interfaces for optional behavior
A policy boolean deliberately enables a family of allow rules, so inspect its policy documentation and blast radius before changing it. setsebool without -P changes runtime state; -P writes persistent local policy and can take longer. Likewise, a daemon listening on a non-standard port may need a persistent semanage port mapping. Check existing assignments first: use -a only for an unassigned port and -m only when intentionally changing an existing local assignment.
getsebool httpd_can_network_connect
semanage boolean -l | grep '^httpd_can_network_connect'
sudo semanage port -l | grep '^http_port_t'
sudo semanage port -a -t http_port_t -p tcp 8443 Constrain and reverse any temporary reduction in enforcement
Whole-system permissive mode allows every otherwise-denied operation and should be a short, approved diagnostic exception with active monitoring and an immediate setenforce 1 recovery step. A permissive domain limits the weakened scope, but semanage permissive creates a persistent local customization—it is not temporary merely because it is used for debugging. Remove it after evidence collection and verify the service again under enforcement. Avoid disabling SELinux; files created while disabled may be unlabeled and re-enablement requires careful relabeling.
sudo semanage permissive -a httpd_t
sudo ausearch -m AVC,USER_AVC -ts recent
sudo semanage permissive -d httpd_t
getenforce Interrogate existing policy before considering a local module
Use service-specific SELinux manual pages, sesearch, booleans, port types, and file types to determine whether the shipped policy already models the requirement. Inventory local modules and their priorities so an old override is not mistaken for vendor behavior. A local module is the last step for a legitimate access pattern that has no supported interface; build it from a reviewed minimal design, version its source, test on matching policy versions, and retain a verified uninstall path.
man httpd_selinux
sesearch -A -s httpd_t -t httpd_sys_content_t -c file -p read
sudo semodule -lfull
sudo semanage fcontext -l -C Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- Red HatUsing SELinux in Red Hat Enterprise Linux 10docs.redhat.com
- Red HatConfiguring SELinux for Applications and Services with Non-standard Configurationsdocs.redhat.com
- Red HatTroubleshooting Problems Related to SELinuxdocs.redhat.com
- SELinux Projectsemanage-fcontext(8)man7.org
- SELinux Projectsetsebool(8)man7.org
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



