Enable SELinux Enforcing Mode on CentOS 7 and CentOS Stream 8 – Practical Guide
Step‑by‑step guide to switch CentOS 7 or CentOS Stream 8 to SELinux enforcing mode, verify the change, diagnose denials with audit2why/audit2allow, and roll back safely if services break.
23 Jun 2026, 07:47 UTC

Desired Outcome
Switch the system from permissive or disabled SELinux state to enforcing mode so that the kernel actively blocks actions violating policy while keeping critical services operational.
Prerequisites
- A supported release: CentOS 7 (7.9 or later) or CentOS Stream 8 (note: both are end‑of‑life as of 2024; consider migrating to Rocky Linux, AlmaLinux, or RHEL for long‑term support).
- Root access or a user with
sudoprivileges capable of editing/etc/selinux/configand runningsetenforce. - Access to the system console or a reliable remote session (SSH) that will survive a reboot.
- The
policycoreutils-python-utilspackage on CentOS Stream 8 orpolicycoreutils-pythonon CentOS 7 installed (providesaudit2whyandaudit2allow). Install with: - CentOS Stream 8:
sudo dnf install policycoreutils-python-utils - CentOS 7:
sudo yum install policycoreutils-python - Current SELinux state is not
disabledin/etc/selinux/config; if it is, a reboot is mandatory and the kernel must load the SELinux policy at boot.
Check Current State Before Changes
Run the following commands on the target host to establish a baseline:
getenforce
cat /etc/selinux/config | grep -E '^SELINUX='
sestatus
getenforce prints the runtime mode (Enforcing, Permissive, or Disabled). sestatus shows whether the policy is loaded and the mode from the config file. If the config line reads SELINUX=disabled, you must edit the file and reboot; setenforce 1 alone will not work because the kernel never loaded the policy.
Procedure: Switch to Enforcing Mode
1. Edit the persistent configuration
sudo vi /etc/selinux/config
(You can use vim or nano if preferred.) Locate the line starting with SELINUX= and change it to:
SELINUX=enforcing
Leave SELINUXTYPE=targeted unchanged. Save and exit the editor.
2. Apply the change immediately (optional but recommended)
sudo setenforce 1
This command switches the running kernel to enforcing mode without a reboot. It requires the policy to already be loaded (i.e., the system was not booted with SELINUX=disabled). If the command returns an error such as setenforce: SELinux is disabled, skip to step 3.
3. Reboot if the system was previously disabled
sudo reboot
A reboot forces the kernel to load the SELinux policy and start in enforcing mode per the updated config file.
Verification Steps
Confirm runtime mode
getenforce
# Expected output: Enforcing
Confirm persistent configuration
grep '^SELINUX=' /etc/selinux/config
# Expected output: SELINUX=enforcing
Ensure audit daemon is running
sudo systemctl status auditd
# If inactive, start it:
sudo systemctl start auditd
sudo systemctl enable auditd
Check for new AVC denials
After the mode switch and after exercising key services (web server, database, custom daemons), run:
# Using ausearch (requires auditd running)
sudo ausearch -m AVC -ts recent
# Optional: include USER_AVC if desired
# sudo ausearch -m AVC,USER_AVC -ts recent
# If auditd is not running, check the journal:
sudo journalctl -t setroubleshoot -since "10 minutes ago"
Any type=AVC lines with denied indicate actions blocked by policy.
Handling Denials: Diagnose and Create Local Policy
When a service fails, capture the relevant denial and generate a loadable module:
# 1. Identify the denial for a specific service (example: httpd)
sudo ausearch -m AVC -c httpd -ts recent | audit2why
# 2. If the denial is expected and safe, create a custom module
sudo ausearch -m AVC -c httpd -ts recent | audit2allow -M httpd_local
# 3. Install the module
sudo semodule -i httpd_local.pp
Risk: Blindly allowing all denials weakens the security posture. Review each audit2why explanation; only create modules for legitimate application behavior (e.g., a web server reading a non‑standard document root).
Rollback Procedure
If enforcing mode breaks critical services and policy adjustments cannot be made in time:
# Temporary runtime rollback (persists until reboot)
sudo setenforce 0
# Persistent rollback
sudo vi /etc/selinux/config
# Change SELINUX=enforcing back to SELINUX=permissive
sudo reboot
Use permissive rather than disabled so the policy remains loaded and denials continue to be logged for later analysis.
Limitations and Caveats
- CentOS 7 reached end of life June 30, 2024; CentOS Stream 8 reached end of life May 31, 2024. Both are no longer receiving security updates.
- Systems with third‑party kernel modules (e.g., proprietary drivers, virtualization guests with older tools) may generate denials that cannot be resolved without vendor updates.
- Container runtimes (Podman, Docker) manage their own SELinux labels; host enforcing mode does not automatically confine container processes without proper labeling.
Practical Verification Checklist
getenforcereturnsEnforcing./etc/selinux/configcontains exactlySELINUX=enforcing.- The audit daemon (
auditd) is active and enabled. - No new AVC denials for core services (sshd, systemd, network, storage) after a reboot and typical workload.
- Custom policy modules (if any) listed by
semodule -l | grep _localare documented and version‑controlled.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.