How to Configure SELinux Modes on Rocky Linux
It is safer to first check the problem and modify the necessary policies rather than completely turning off SELinux (Security-Enhanced Linux) on Rocky Linux. If diagnostics are needed, temporarily use permissive mode, and consider permanent deactivation only when there is no other solution due to incompatible software.
Check current SELinux status
getenforce shows the current operating mode in a single line, and sestatus shows detailed information such as the mode and policy in the configuration file.
getenforce sestatus
| Modes | Meaning |
|---|---|
Enforcing |
Logs policy violations and actually enforces them. Recommended state for production servers. |
Permissive |
Logs policy violations but does not enforce them. Suitable for cause analysis and policy testing. |
Disabled |
SELinux is not functioning, and file security context management is also stopped. |
Temporarily use Permissive mode
Change only for the current boot
The following command will stop blocking only until the next reboot. Use it to narrow down whether the issue is caused by SELinux, and reapply immediately once verification is complete.
sudo setenforce 0 getenforce
Return to Enforcing mode
sudo setenforce 1 getenforce
The fact that the problem disappears in Permissive mode only indicates a potential SELinux-related issue, and does not mean that SELinux should be disabled. Check the audit logs to modify necessary file contexts, booleans, or port types.
Check the cause of the block
View recent AVC denial records
SELinux access denials are recorded in the audit log as AVC (Access Vector Cache) messages. Recent records can be viewed as follows.
sudo ausearch -m AVC,USER_AVC -ts recent
If ausearch is not available, check the audit package and the status of the service. Examine the process in the log, the target path, and requested permissions to determine if they match the actual service behavior.
File Security Context Restoration
If the security context of web documents or service data is incorrect, it is easier to register a permanent rule and apply it with restorecon rather than making arbitrary chcon changes.
sudo semanage fcontext -a -t httpd_sys_content_t '/srv/www(/.*)?' sudo restorecon -Rv /srv/www
The semanage command is usually provided by the policycoreutils-python-utils package. Directories requiring write permissions should be assigned a separate type suitable for their purpose, and example types should not be applied indiscriminately.
Adjusting Booleans and Non-Standard Ports
Allowing Service Functions with Booleans
Selectable features provided by the policy in advance can be enabled using SELinux booleans. Check the current values and descriptions, then permanently apply only the necessary items.
getsebool -a | grep httpd sudo setsebool -P httpd_can_network_connect on
Registering Port Types for Services
If a service uses a non-default port, an SELinux port policy may be required in addition to firewall allowances. Check existing mappings first, then add new ones.
sudo semanage port -l | grep http_port_t sudo semanage port -a -t http_port_t -p tcp 8088
You may need -m instead of -a to change the type of an already registered port. First, check if the port is used by another service.
Keep Permissive mode after boot
To maintain record-only mode even after a reboot while investigating application compatibility, back up /etc/selinux/config and set SELINUX=permissive.
sudo cp -a /etc/selinux/config /etc/selinux/config.backup sudo sed -i 's/^SELINUX=.*/SELINUX=permissive/' /etc/selinux/config grep '^SELINUX=' /etc/selinux/config
The value in the configuration file will be applied at the next boot. The current mode can be separately changed with setenforce 0 or verified after the planned reboot.
If you need to completely disable SELinux
If there are no other solutions and the risks have been reviewed, secure a backup and console access, change SELINUX=disabled in the configuration file, and reboot.
sudo cp -a /etc/selinux/config /etc/selinux/config.before-disabled sudo sed -i 's/^SELINUX=.*/SELINUX=disabled/' /etc/selinux/config sudo reboot
During the disabled period, SELinux contexts on files may not stay up to date. When re-enabling later, first boot into Permissive mode and plan for a full relabeling operation and service verification, as reboot time may significantly increase depending on the number of files.
Recommended troubleshooting order
- Check the current status with
getenforceandsestatus. - First, check the service logs, file permissions, and firewall.
- If necessary, temporarily switch to Permissive mode and compare the symptoms.
- Check the actual denial records with
ausearch. - Modify only the minimum scope with the correct file context, Boolean, or port type.
- Return to Enforcing mode and re-verify functionality and logs.
Reference Documents
The Rocky Linux SELinux Learning Guide explains the basic principles of modes, security contexts, Booleans, and troubleshooting.









