whatis selinux
SELinux
Also known as: Security-Enhanced Linux
A mandatory access control system that labels every file and process and enforces policy on what they may access, default on Fedora and RHEL.
What Is SELinux in Linux?
Normal Unix permissions let a file's owner decide access. SELinux adds a system-wide policy on top: even a process running as root can only touch files whose labels its policy allows. A compromised web server confined by SELinux cannot read home directories.
Denials appear in the audit log. Most issues are fixed by restoring correct labels with restorecon or toggling a boolean, not by disabling SELinux.
Example
getenforce
ls -Z /var/www/html
sudo restorecon -Rv /var/www/html Learn more about SELinux
- SELinux Explained SELinux (Security-Enhanced Linux) is a mandatory access control system built into the Linux kernel. This guide explains how SELinux works, what contexts and policies mean, how to read denials, and how to write rules with audit2allow.
- auditd: The Linux Audit Framework Explained How auditd records syscalls at the kernel level, why that makes it tamper-evident in a way application logs are not, and how to write rules without drowning in events.