{"id":12460,"date":"2026-08-03T09:31:04","date_gmt":"2026-08-03T07:31:04","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=12460"},"modified":"2026-08-03T09:31:08","modified_gmt":"2026-08-03T07:31:08","slug":"selinux-on-almalinux-explained-modes-policies-contexts-and-safe-troubleshooting","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/selinux-on-almalinux-explained-modes-policies-contexts-and-safe-troubleshooting\/","title":{"rendered":"SELinux on AlmaLinux Explained: Modes, Policies, Contexts, and Safe Troubleshooting"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">SELinux on AlmaLinux is a security system that controls which applications and services can access system resources. It adds rules to the standard Unix permission model. As a result, a web server, file-sharing service, or custom application can be blocked even when the file owner, group, and permissions appear to be correct.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SELinux uses labels, known as security contexts, and policy rules to decide whether an action is allowed. The safest way to resolve a denial is to identify the blocked action and adjust the label, policy setting, or service configuration. Disabling SELinux should not be the first response.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/selinux-on-almalinux-explained-modes-policies-contexts-and-safe-troubleshooting\/#How_SELinux_protects_AlmaLinux_services\" >How SELinux protects AlmaLinux services<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/selinux-on-almalinux-explained-modes-policies-contexts-and-safe-troubleshooting\/#SELinux_operating_modes\" >SELinux operating modes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/selinux-on-almalinux-explained-modes-policies-contexts-and-safe-troubleshooting\/#Security_contexts_and_labels\" >Security contexts and labels<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/selinux-on-almalinux-explained-modes-policies-contexts-and-safe-troubleshooting\/#How_to_investigate_an_SELinux_denial\" >How to investigate an SELinux denial<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/selinux-on-almalinux-explained-modes-policies-contexts-and-safe-troubleshooting\/#Common_remedies_for_services_and_file_sharing\" >Common remedies for services and file sharing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/selinux-on-almalinux-explained-modes-policies-contexts-and-safe-troubleshooting\/#SELinux_versus_Unix_permissions\" >SELinux versus Unix permissions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/selinux-on-almalinux-explained-modes-policies-contexts-and-safe-troubleshooting\/#When_permissive_testing_does_not_solve_the_problem\" >When permissive testing does not solve the problem<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_SELinux_protects_AlmaLinux_services\"><\/span>How SELinux protects AlmaLinux services<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-3023225731\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">Unix permissions answer questions such as whether a process runs as a particular user and whether that user can read a file. SELinux adds another check. Its policy defines which types of processes may access which types of files, directories, ports, and system resources.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, a web server process may run as the correct user and still be unable to read files in a newly created directory. The directory may have a suitable Unix owner and mode, but its SELinux context may not identify it as web content. SELinux blocks the access because the process and resource do not match an allowed policy rule.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"SELinux_operating_modes\"><\/span>SELinux operating modes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Mode<\/th><th>Behaviour<\/th><th>Recommended use<\/th><\/tr><\/thead><tbody><tr><td>Enforcing<\/td><td>SELinux applies policy and blocks actions that are not allowed.<\/td><td>Normal operation on a protected server.<\/td><\/tr><tr><td>Permissive<\/td><td>SELinux does not block the action, but records a denial in the audit log.<\/td><td>Short diagnostic tests or policy development.<\/td><\/tr><tr><td>Disabled<\/td><td>SELinux is not loaded and does not provide enforcement or denial records.<\/td><td>Only when a documented platform requirement makes it necessary.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Check the current mode with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>getenforce\nsestatus<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You can temporarily change between enforcing and permissive mode with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo setenforce 1\nsudo setenforce 0<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A temporary permissive test ends when the system is restarted. It can help confirm that SELinux is related to a problem, but it does not identify the correct permanent fix. Avoid leaving production systems in permissive mode. Disabling SELinux requires changing its configuration and restarting the system, and it removes an important layer of protection.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Security_contexts_and_labels\"><\/span>Security contexts and labels<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A security context is a label attached to a file, directory, process, port, or other resource. The label helps SELinux match a resource to its policy. View file labels with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ls -Z \/path\/to\/file\nls -Zd \/path\/to\/directory<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">View process labels with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ps -eZ<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A copied or newly created file can have a context that does not fit the service using it. For example, content moved into a web directory may keep a label from its original location. The Unix permissions can remain correct while the web server is still denied access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use <code>restorecon<\/code> when the expected label is already defined by the system policy:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo restorecon -Rv \/path\/to\/content<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For a directory that must keep a custom location, define the expected label with <code>semanage fcontext<\/code>, then apply it with <code>restorecon<\/code>. For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo semanage fcontext -a -t httpd_sys_content_t '\/srv\/site(\/.*)?'\nsudo restorecon -Rv \/srv\/site<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The exact context depends on the service and the access required. Web content, writable application data, and shared files may need different types. Do not copy a label from an unrelated service without checking the policy requirement.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_investigate_an_SELinux_denial\"><\/span>How to investigate an SELinux denial<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Record the failed action.<\/strong> Note the service, file or directory, port, user action, and approximate time.<\/li>\n\n\n\n<li><strong>Check the audit records.<\/strong> Search recent AVC denial messages with <code>ausearch<\/code>:<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo ausearch -m AVC -ts recent<\/code><\/pre>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\">\n<li><strong>Read the denial details.<\/strong> Look for the process type, target type, requested action, and resource path. These fields show what SELinux blocked.<\/li>\n<li><strong>Check the current labels.<\/strong> Compare the labels on the process and resource with the labels expected for that service.<\/li>\n<li><strong>Test one change at a time.<\/strong> Correct a label, service setting, Boolean, or port definition, then repeat the original action and check the audit log again.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Tools such as <code>audit2why<\/code> can help describe why a denial occurred. Tools such as <code>audit2allow<\/code> can propose a local policy rule, but a generated rule should not be applied automatically. It may allow more access than the application needs and can hide an incorrect label or unsafe service design.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Common_remedies_for_services_and_file_sharing\"><\/span>Common remedies for services and file sharing<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For web servers, first verify that the site files have the correct web content context. If the application must write to a directory, use the specific writable type required by the web server policy rather than making the whole site writable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For file-sharing services, check that shared directories have the context intended for that service. A directory can be readable through Unix permissions and still be blocked because its SELinux type is not approved for sharing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For an application using a non-standard port, check whether that port is labelled for the service. A custom service may also need a policy setting that permits its required network or file access. Change only the setting needed for the documented workload, and keep the change persistent when appropriate.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"SELinux_versus_Unix_permissions\"><\/span>SELinux versus Unix permissions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Check<\/th><th>What it controls<\/th><\/tr><\/thead><tbody><tr><td>Unix permissions<\/td><td>Access based on file owner, group, mode, and process user.<\/td><\/tr><tr><td>SELinux policy<\/td><td>Access based on the process domain, resource context, and allowed actions.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Both checks must allow the action. Changing Unix permissions cannot fix a denial caused by an incorrect SELinux context. Turning SELinux off may make the action work, but it also removes policy enforcement and leaves the original configuration issue unresolved.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"When_permissive_testing_does_not_solve_the_problem\"><\/span>When permissive testing does not solve the problem<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If the action still fails in permissive mode, SELinux may not be the cause. Check the service configuration, Unix permissions, application settings, network access, and logs for the affected service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the action works only in permissive mode, return to enforcing mode after testing and use the AVC record to identify the required change. Contact support or the policy maintainer when the denial involves a custom service, a complex application, or a rule that cannot be safely narrowed.<\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[42],"manual_kb_tag":[],"class_list":["post-12460","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-miscellaneous"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/12460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/12460\/revisions"}],"predecessor-version":[{"id":12461,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/12460\/revisions\/12461"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=12460"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=12460"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=12460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}