Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

What Is SELinux and How Does It Work?

SELinux is a security tool built into many Linux servers. This guide explains what it does and how to check it.

Web Hosting2 min read6 steps

What is SELinux?

SELinux stands for Security-Enhanced Linux. It is an extra security guard inside the server. Think of a school with a front gate and also locked classroom doors. Even if someone gets past the gate, the classroom doors still stop them.

Linux already has normal permissions. These say which user can read, write or run a file. SELinux adds a second layer on top. It decides what each program is allowed to touch, even when normal permissions say yes.

How does it work?

Every file, folder and program gets a label. The label is called a context. SELinux also has a set of rules called a policy. The policy says which labels may talk to which other labels.

For example, the web server program may read website files. It may not read the secret password files of the system. If a hacker takes over the web server, SELinux still blocks the harmful moves.

The three modes

  • Enforcing: SELinux blocks anything the policy does not allow.
  • Permissive: SELinux does not block. It only writes warnings in a log. This is good for testing.
  • Disabled: SELinux is off.

Steps to check SELinux

These steps need root access. Root access means full control of the server. VPS and dedicated server customers have it.

  1. Log in to your server with SSH. SSH is a safe way to type commands on a remote server.
  2. Type the command below and press Enter.
getenforce

This prints the current mode: Enforcing, Permissive or Disabled.

  1. For more detail, type the next command.
sestatus

This shows the mode, the policy name and more.

Switching to permissive for a test

If a program fails and you think SELinux is the cause, test it for a short time.

  1. Run the command below.
setenforce 0

This sets permissive mode until the next restart.

  1. Try your program again. If it now works, SELinux was blocking it.
  2. Turn protection back on with the next command.
setenforce 1
Tip: Do not leave SELinux off for good. Fix the label or rule instead. Ask Hostvento support if you are unsure.

Quick recap

  • SELinux is a second security layer on Linux servers.
  • It uses labels and a policy to limit what programs can do.
  • The modes are Enforcing, Permissive and Disabled.
  • Use getenforce to see the mode.
  • Use permissive mode only for short tests.