How to Enable and Verify SELinux Enforcing Mode on CentOS 8 and CentOS Stream
Enable SELinux in enforcing mode on CentOS 8/Stream, tweak the config, toggle at runtime, and verify policy enforcement with audit logs and context checks.
07 Nov 2025, 04:43 UTC

Why SELinux Enforcing Matters
SELinux (Security‑Enhanced Linux) adds a mandatory access control layer that restricts what processes can do, even if they run as root. On CentOS 8 and CentOS Stream, SELinux is enabled by default in enforcing mode, meaning policy denials are actively blocked and logged. If you inadvertently disable it or run in permissive mode, you lose this protection and may not notice violations until a breach occurs.
Step 1 – Check Current Mode
# getenforce
Enforcing
The getenforce command reports the runtime state. A healthy production system should output Enforcing. If it shows Permissive or Disabled, you need to change the configuration file and reboot.
Step 2 – Configure /etc/selinux/config
The primary configuration file lives at /etc/selinux/config. Edit it with root privileges:
# vi /etc/selinux/config
# Make sure the line reads:
SELINUX=enforcing
# Optional: set the policy type
SELINUXTYPE=targeted
Explanation of fields:
SELINUXcan beenforcing,permissive, ordisabled.SELINUXTYPEselects the policy set;targetedis the default and covers most services.
After editing, reboot to apply the change:
# reboot
Upon restart, run getenforce again to confirm.
Step 3 – Toggle at Runtime (Optional)
If you need to switch modes without rebooting (e.g., during troubleshooting), use setenforce:
# setenforce 0 # Switch to permissive
# setenforce 1 # Switch back to enforcing
Only root can run setenforce. Remember that changing runtime state does not alter the config file; a reboot will revert to the configured mode.
Step 4 – Verify Policy Enforcement
1. Check audit logs for denials:
# tail -n 20 /var/log/audit/audit.log | grep AVC
AVC (Access Vector Cache) entries indicate policy blocks. A clean system under normal use should have few or none. If you see repeated denials for a service, you may need to adjust file contexts.
2. Inspect file contexts with semanage (part of policycoreutils-python-utils):
# semanage fcontext -l | grep '/var/www/html'
Ensure the expected type (e.g., httpd_sys_content_t) is applied. If contexts are wrong, restore them:
# restorecon -Rv /var/www/html
Concrete Example: Running Apache Securely
Assume you installed httpd and want to confirm SELinux blocks any attempt to read /etc/shadow from the web server:
# cat /var/www/html/index.html
<html><body>Hello</body></html>
# echo 'cat /etc/shadow' | nc localhost 80
The request fails, and an AVC denial appears in /var/log/audit/audit.log. You can view it with:
# ausearch -m avc -ts recent | tail -n 5
That confirms SELinux is actively enforcing policy for the web server.
Common Pitfalls & Limits
- Disabling SELinux: Setting
SELINUX=disabledremoves all policy enforcement. Do not use this in production. - Permissive Mode:
SELINUX=permissivelogs denials but allows them. Useful for debugging, but leave it only temporarily. - Incorrect File Contexts: Mislabeling files (e.g., moving a web document outside
/var/wwwwithout updating contexts) can cause services to fail. Usesemanage fcontextandrestoreconto fix. - Policy Updates: After installing new packages, run
restorecon -Rv /pathto apply default contexts. Failing to do so can lead to denied operations. - Audit Log Rotation: Verify that
/etc/audit/auditd.confretains enough space; otherwise, denials may be lost.
Practical Check: Is SELinux Truly Enforcing?
Run a quick test that should be blocked:
# touch /tmp/testfile
# chcon -t bin_t /tmp/testfile
# /usr/bin/ls /tmp/testfile # executed as a non‑root user
If SELinux is enforcing, the command will fail with an AVC denial logged in /var/log/audit/audit.log. If it succeeds, you have either permissive mode or misconfigured contexts.
Conclusion
Enabling SELinux in enforcing mode on CentOS 8 or CentOS Stream is a straightforward process: set SELINUX=enforcing in /etc/selinux/config, reboot, and verify with getenforce and audit logs. Use setenforce for temporary mode changes, and keep an eye on file contexts with semanage and restorecon. Avoid disabling SELinux; if you must, document the risk and plan to re‑enable it as soon as possible.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.