1. Topics
  2. Security
  3. What is SELinux (Security-Enhanced Linux)?

What is SELinux (Security-Enhanced Linux)?

CopiedCopy failedCopy URL

Security-Enhanced Linux (SELinux) is a security architecture for Linux® systems that allows administrators more control over who can access the system. It was originally developed by the United States National Security Agency (NSA) as a series of patches to the Linux kernel using Linux Security Modules (LSM).  

SELinux was released to the open source community in 2000, and was integrated into the upstream Linux kernel in 2003.

Try an SELinux-enabled operating system at no cost


 

SELinux defines access controls for the applications, processes, and files on a system. It uses security policies, which are a set of rules that tell SELinux what can or can’t be accessed, to enforce the access allowed by a policy. 

When an application or process, known as a subject, makes a request to access an object, like a file, SELinux checks with an access vector cache (AVC), where permissions are cached for subjects and objects.

If SELinux is unable to make a decision about access based on the cached permissions, it sends the request to the security server. The security server checks for the security context of the app or process and the file. Security context is applied from the SELinux policy database. Permission is then granted or denied. 

If permission is denied, an avc: denied message is recorded in /var/log/audit/audit.log. If auditd is not running, the same messages can also appear in the system journal or /var/log/messages.

How secure is your cloud? Take our assessment

How to configure SELinux 

There are a number of ways that you can configure SELinux to protect your system. The most common are targeted policy or multilevel security (MLS).

Targeted policy is the default option and covers a range of processes, tasks, and services. MLS can be complicated and is typically only used by government organizations. 

You can see your system’s security level by viewing the /etc/sysconfig/selinux file. The file will have a section that shows you whether SELinux is in permissive mode, enforcing mode, or disabled, and which policy is supposed to be loaded.

  • Enforcing mode: the default, and recommended, mode of operation. SELinux operates normally, enforcing the loaded security policy on the entire system.
  • Permissive mode: the system acts as if SELinux is enforcing the loaded security policy, including labeling objects and emitting access denial entries in the logs, but it does not actually deny any operations. While not recommended for production systems, permissive mode can be helpful for SELinux policy development and debugging.
  • Disabled mode: use is strongly discouraged. Not only does the system avoid enforcing the SELinux policy, it also avoids labeling any persistent objects such as files, making it difficult to enable SELinux in the future.

SELinux labeling and type enforcement 

Type enforcement and labeling are the most important concepts for SELinux.

SELinux works as a labeling system, which means that all the files, processes, and ports in a system have an SELinux label associated with them. Labels are a logical way of grouping things together. The kernel manages the labels during boot.

SELinux uses type enforcement to enforce a policy that is defined on the system. Type enforcement is the part of an SELinux policy that defines whether a process running with a certain type can access a file labeled with a certain type.

SELinux labels consist of 4 fields:

  • user
  • role 
  • type
  • security level

The type label is the most important field because standard SELinux policies use it to control system permissions. The user, role, and level fields are reserved for advanced configurations, such as multilevel security (MLS) or multicategory security (MCS).

Enabling SELinux

If SELinux has been disabled in your environment, you can enable SELinux by editing /etc/selinux/config and setting SELINUX=permissive. Since SELinux was not enabled, you should not set it to enforcing mode right away because the system will likely have things mislabeled that can keep it from booting.  

You can force the system to automatically relabel the filesystem by creating an empty file named .autorelabel in the root directory and then rebooting. If the system has too many errors, you should reboot while in permissive mode in order for the boot to succeed. After everything has been relabeled, set SELinux to enforcing mode with /etc/selinux/config and reboot, or run setenforce 1. 

If a sysadmin is less familiar with the command line, there are graphic tools available that can be used to manage SELinux. 

SELinux provides an additional layer of security for your system that is built into Linux distributions. It should remain on so that it can protect your system if it is ever compromised.

Optimize Linux security with Red Hat

Red Hat resources

Traditionally, Linux and UNIX systems have used DAC. SELinux is an example of a MAC system for Linux. 

With DAC, files and processes have owners. You can have the user own a file, a group own a file, or other, which can be anyone else. Users have the ability to change permissions on their own files.

The root user has full access control with a DAC system. If you have root access, then you can access any other user’s files or do whatever you want on the system. 

Unlike standard Linux permissions, SELinux uses centrally managed policies to control access. Because an action requires permission from both standard file settings (DAC) and SELinux, it acts as a safety net. Even if a directory's permissions are accidentally set to world-readable (chmod 777), SELinux can still block unauthorized processes from accessing it.

SELinux policies let you be specific and cover a large number of processes. You can make changes with SELinux to limit access between users, files, directories, and more.

Booleans are on/off settings for functions in SELinux. There are hundreds of settings that can turn SELinux capabilities on or off, and many are already predefined. You can find out which booleans have already been set in your system by running getsebool -a.

Errors in SELinux are typically caused by one of these common problems:

1. The labels are wrong (incorrect context)

This happens when files or directories have the wrong security context, often because they were moved from one location to another.

  • The fix: Reset the files to their expected default system labels using restorecon:
    • sudo restorecon -vR /path/to/directory

2. Services are configured in nonstandard locations

This happens when you change a service's default data directory (e.g. moving database files or web server files to a custom storage drive). SELinux blocks the service because it doesn't recognize the new path.

  • The fix: Inform the SELinux policy database about the new location and apply the labels:
    • sudo semanage fcontext -a -t <appropriate_context_t> "/custom/path(/.*)?"
    • sudo restorecon -R -v /custom/path

3. Binding to nonstandard network ports

This happens when you change a service's default listening port (e.g. changing SSH from port 22 to 2222). SELinux will automatically block the service from starting up on an unauthorized port.

  • The fix: Register the new port to the correct SELinux port type:
    • sudo semanage port -a -t <port_type_t> -p tcp <port_number>

4. A Boolean needs adjusting (policy toggles)

SELinux uses conditional switches called "Booleans" to allow or deny specific features (e.g., allowing a web server to send email or connect to a database). If an application tries to perform one of these actions but the boolean is turned off, it triggers a denial.

  • The fix: Enable the appropriate Boolean toggle permanently:
    • sudo setsebool -P <boolean_name> on

5. The system has been compromised (or a policy bug exists)

If your labels, paths, ports, and Booleans are all correct, you may be facing a software bug in the policy itself, or a genuine security compromise where a process is attempting malicious activity.

  • The fix: Review the audit logs using sealert to determine if a custom policy module needs to be generated, or immediately initiate incident response protocols if a compromise is suspected:
    • sudo sealert -a /var/log/audit/audit.log

View additional troubleshooting resources 

Red Hat Enterprise Linux is the world’s leading open source Linux platform, helping you mitigate risk, enforce security configuration and policy, and streamline compliance strategy. 

Red Hat Enterprise Linux system roles are a collection of supported Ansible® roles that ensure consistent workflows and optimize the execution of manual tasks. System roles help teams automate security workflows and maintain them over time, at scale, and with minimal resources, as well as simplify governance and compliance requirements. With the SELinux system role, you can automate the deployment and management of SELinux. This includes: 

  • Enabling SELinux with enforcing or permissive modes to ensure consistency of controls.
  • Customizing SELinux policy booleans, file contexts, ports, and logins to meet your requirements.
  • Utilizing the system role to reconcile file contexts on specified files or directories.

Learn more about Red Hat Enterprise Linux system roles

Red Hat Enterprise Linux 10

Discover how Red Hat Enterprise Linux 10 addresses today’s most pressing IT challenges, from the Linux skills gap to post-quantum security.

All Red Hat product trials

Our no-cost product trials help you gain hands-on experience, prepare for a certification, or assess if a product is right for your organization.

Keep reading

Shift left vs. shift right

To shift left and shift right is to implement continuous testing throughout each stage of the software development lifecycle.

What is an SBOM?

Understand the role of a software bill of materials (SBOM) in software transparency, risk management, and protecting your supply chain from vulnerabilities.

What is a CVE?

CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws.

Security resources

Related articles