whatis selinux

SELinux

Also known as: Security-Enhanced Linux

A mandatory access control system that labels every file and process and enforces policy on what they may access, default on Fedora and RHEL.

What Is SELinux in Linux?

Normal Unix permissions let a file's owner decide access. SELinux adds a system-wide policy on top: even a process running as root can only touch files whose labels its policy allows. A compromised web server confined by SELinux cannot read home directories.

Denials appear in the audit log. Most issues are fixed by restoring correct labels with restorecon or toggling a boolean, not by disabling SELinux.

Example

getenforce
ls -Z /var/www/html
sudo restorecon -Rv /var/www/html