How to Configure SELinux Modes on Rocky Linux

It is safer to first check the problem and modify the necessary policies rather than completely turning off SELinux (Security-Enhanced Linux) on Rocky Linux. If diagnostics are needed, temporarily use permissive mode, and consider permanent deactivation only when there is no other solution due to incompatible software.

Check current SELinux status

getenforce shows the current operating mode in a single line, and sestatus shows detailed information such as the mode and policy in the configuration file.

getenforce
sestatus
Modes Meaning
Enforcing Logs policy violations and actually enforces them. Recommended state for production servers.
Permissive Logs policy violations but does not enforce them. Suitable for cause analysis and policy testing.
Disabled SELinux is not functioning, and file security context management is also stopped.

Temporarily use Permissive mode

Change only for the current boot

The following command will stop blocking only until the next reboot. Use it to narrow down whether the issue is caused by SELinux, and reapply immediately once verification is complete.

sudo setenforce 0
getenforce

Return to Enforcing mode

sudo setenforce 1
getenforce

The fact that the problem disappears in Permissive mode only indicates a potential SELinux-related issue, and does not mean that SELinux should be disabled. Check the audit logs to modify necessary file contexts, booleans, or port types.

Check the cause of the block

View recent AVC denial records

SELinux access denials are recorded in the audit log as AVC (Access Vector Cache) messages. Recent records can be viewed as follows.

sudo ausearch -m AVC,USER_AVC -ts recent

If ausearch is not available, check the audit package and the status of the service. Examine the process in the log, the target path, and requested permissions to determine if they match the actual service behavior.

File Security Context Restoration

If the security context of web documents or service data is incorrect, it is easier to register a permanent rule and apply it with restorecon rather than making arbitrary chcon changes.

sudo semanage fcontext -a -t httpd_sys_content_t '/srv/www(/.*)?'
sudo restorecon -Rv /srv/www

The semanage command is usually provided by the policycoreutils-python-utils package. Directories requiring write permissions should be assigned a separate type suitable for their purpose, and example types should not be applied indiscriminately.

Adjusting Booleans and Non-Standard Ports

Allowing Service Functions with Booleans

Selectable features provided by the policy in advance can be enabled using SELinux booleans. Check the current values and descriptions, then permanently apply only the necessary items.

getsebool -a | grep httpd
sudo setsebool -P httpd_can_network_connect on

Registering Port Types for Services

If a service uses a non-default port, an SELinux port policy may be required in addition to firewall allowances. Check existing mappings first, then add new ones.

sudo semanage port -l | grep http_port_t
sudo semanage port -a -t http_port_t -p tcp 8088

You may need -m instead of -a to change the type of an already registered port. First, check if the port is used by another service.

Keep Permissive mode after boot

To maintain record-only mode even after a reboot while investigating application compatibility, back up /etc/selinux/config and set SELINUX=permissive.

sudo cp -a /etc/selinux/config /etc/selinux/config.backup
sudo sed -i 's/^SELINUX=.*/SELINUX=permissive/' /etc/selinux/config
grep '^SELINUX=' /etc/selinux/config

The value in the configuration file will be applied at the next boot. The current mode can be separately changed with setenforce 0 or verified after the planned reboot.

If you need to completely disable SELinux

If there are no other solutions and the risks have been reviewed, secure a backup and console access, change SELINUX=disabled in the configuration file, and reboot.

sudo cp -a /etc/selinux/config /etc/selinux/config.before-disabled
sudo sed -i 's/^SELINUX=.*/SELINUX=disabled/' /etc/selinux/config
sudo reboot

During the disabled period, SELinux contexts on files may not stay up to date. When re-enabling later, first boot into Permissive mode and plan for a full relabeling operation and service verification, as reboot time may significantly increase depending on the number of files.

Recommended troubleshooting order

  1. Check the current status with getenforce and sestatus.
  2. First, check the service logs, file permissions, and firewall.
  3. If necessary, temporarily switch to Permissive mode and compare the symptoms.
  4. Check the actual denial records with ausearch.
  5. Modify only the minimum scope with the correct file context, Boolean, or port type.
  6. Return to Enforcing mode and re-verify functionality and logs.

Reference Documents

The Rocky Linux SELinux Learning Guide explains the basic principles of modes, security contexts, Booleans, and troubleshooting.

More in This Category
How to Install MariaDB on Rocky Linux

How to Install MariaDB on Rocky Linux

Install MariaDB on Rocky Linux, enable the database service, complete the initial security setup, create a database and account, and verify access.

How to Configure a Static IP Address on Rocky Linux

How to Configure a Static IP Address on Rocky Linux

Configure and verify a static IPv4 address on Rocky Linux with NetworkManager, including the gateway, DNS servers, connection profile, and safe remote-change checks.

How to Change the System Language and Locale on Rocky Linux

How to Change the System Language and Locale on Rocky Linux

Learn how to check and change the system-wide language and locale on Rocky Linux with localectl and glibc language packs. This guide also explains session-only changes, LANG and LC_* precedence, and troubleshooting for broken Korean characters.

How to Install PostgreSQL on Rocky Linux

How to Install PostgreSQL on Rocky Linux

Install PostgreSQL on Rocky Linux, initialize the database cluster, enable the service, create a database and user, and review network and authentication settings.

How to Install a GUI and Remote Desktop on Rocky Linux

How to Install a GUI and Remote Desktop on Rocky Linux

Install a graphical desktop on Rocky Linux, select the graphical boot target, configure remote access, and review firewall and security considerations.

How to List Installed Packages on Rocky Linux

How to List Installed Packages on Rocky Linux

Use DNF and RPM to list, search, count, and inspect installed packages on Rocky Linux and identify which package owns a file.

Rocky Linux Administration Memo: Essential Commands and Configuration Notes

Rocky Linux Administration Memo: Essential Commands and Configuration Notes

A practical Rocky Linux administration reference covering packages, services, networking, storage, security controls, logs, and frequently used maintenance commands.

How to Configure Root SSH Login on Rocky Linux Safely

How to Configure Root SSH Login on Rocky Linux Safely

Review how root SSH login is controlled on Rocky Linux, why direct root access is risky, and how to change and verify sshd settings without losing remote access.

How to Manage firewalld on Rocky Linux: Zones, Services, and Ports

How to Manage firewalld on Rocky Linux: Zones, Services, and Ports

Learn how to manage firewalld on Rocky Linux with firewall-cmd, including active zones, services, custom ports, runtime and permanent rules, rich rules, and NetworkManager integration. The guide emphasizes a safe workflow for remote SSH servers.

How to Change the Hostname on Rocky Linux

How to Change the Hostname on Rocky Linux

Learn how to change a Rocky Linux hostname with hostnamectl, verify the persistent setting, and check name resolution and services afterward.