{"id":2217,"date":"2026-05-29T10:40:20","date_gmt":"2026-05-29T03:40:20","guid":{"rendered":"https:\/\/tutorial.emka.web.id\/?p=2217"},"modified":"2026-05-29T10:40:20","modified_gmt":"2026-05-29T03:40:20","slug":"how-actually-selinux-is-work","status":"publish","type":"post","link":"https:\/\/emka.web.id\/en\/2026\/05\/how-actually-selinux-is-work.html","title":{"rendered":"How Actually SELinux is Work?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">We have all been there. You finish a fresh Fedora installation, you try to run a service or access a specific folder, and suddenly, everything just stops working. Your error logs are silent, your permissions look perfect, but the system is flat-out denying you access. Your first instinct is probably to reach for the &#8220;nuclear option&#8221;: running setenforce 0 to turn SELinux off entirely. We know the temptation is huge because it feels like a quick five-minute fix to get back to work. But we are here to tell you: please don&#8217;t do that.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p class=\"wp-block-paragraph\">When you disable SELinux, you aren&#8217;t just fixing a minor annoyance; you are trading a tiny bit of configuration effort for a completely unconfined system. You are essentially walking away from the most powerful exploit-mitigation layer the Linux kernel has to offer. Instead of turning it off, we want to teach you how to become a pro at it. The real skill isn&#8217;t knowing how to disable security; it is learning how to read the audit logs, identifying exactly what was denied, and applying the narrowest, most precise policy adjustment possible to allow that specific action.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To do this effectively, you only need to master four essential tools. We use ausearch and sealert to read through the denials so you aren&#8217;t hunting through thousands of lines of text blindly. We use semanage port when we need to deal with non-standard ports, setsebool when we need to toggle specific behaviors on or off, and finally, we use semanage fcontext combined with restorecon whenever we are dealing with custom file paths.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before we dive into the &#8220;how-to,&#8221; we need to make sure we are all looking at the same mental model. Think of SELinux as a Mandatory Access Control (MAC) layer that sits on top of your standard Unix permissions. Standard Unix permissions are like the lock on your front door; they ask if a specific user is allowed to read a file. SELinux is more like a high-tech alarm system. Even if someone has the key to the front door, the alarm will still go off if they try to enter a room they aren&#8217;t supposed to be in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a standard Fedora setup, the policy is &#8220;targeted.&#8221; This is a smart design choice because it confines the heavy-hitting system services that talk to the network or run as root\u2014things like Nginx, SSH, PostgreSQL, or Podman\u2014while leaving your interactive user sessions in an &#8220;unconfined&#8221; state. This means you get most of the security benefits without your desktop experience feeling like a constant battle.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To understand how this works in practice, you have to understand &#8220;contexts.&#8221; Every single process, file, and network port on your system carries a label. It looks like a long string of text separated by colons, such as system_u:system_r:httpd_t:s0. While that looks intimidating, you really only need to focus on the &#8220;type&#8221; field, which is usually the third part. For example, if a process is labeled httpd_t, it means it is an Nginx or Apache daemon. If a file is labeled httpd_sys_content_t, it is content that the webserver is allowed to read. The entire security policy is essentially just a massive table of rules that says which types are allowed to interact with other types.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you run a command like ls -Z, you can see these labels in action. You will notice that your SSH binary has a specific execution label, while sensitive files like the shadow password file have highly restricted labels. Even your own shell is labeled as unconfined_t, which is why you can move around freely, while the background daemons are tightly locked down.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most important concepts we need to cover is the &#8220;domain transition.&#8221; This is how a simple binary becomes a powerful daemon. When systemd starts the SSH service, the policy tells the kernel that when an initialization process executes the SSH binary, the resulting process should transition into the sshd_t domain. This ensures that even though the process was started by the system, it immediately enters a restricted &#8220;sandbox&#8221; where it can only do what it is specifically programmed to do. This is why, when you create your own custom systemd services, you might run into trouble; if you don&#8217;t label your executable correctly, it might inherit a generic label that doesn&#8217;t have the permissions it needs to function.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By learning to work with these labels rather than fighting them, you turn SELinux from an obstacle into your greatest ally in building a secure, professional Linux environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have all been there. You finish a fresh Fedora installation, you try to run a service or access a specific folder, and suddenly,&#8230;<\/p>\n","protected":false},"author":27,"featured_media":2218,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[569],"tags":[4312,4313,4314,4315,4316,4317,4318,4319,4320,4321],"class_list":["post-2217","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-computer-security","tag-ausearch-and-sealert-guide","tag-fedora-security-best-practices","tag-hardening-fedora-server-with-selinux","tag-how-to-fix-selinux-denials-fedora","tag-manage-selinux-contexts-fedora","tag-selinux-domain-transitions-explained","tag-selinux-tutorial-for-beginners","tag-selinux-vs-linux-permissions-explained","tag-semanage-port-and-fcontext-tutorial","tag-troubleshooting-selinux-audit-logs"],"_links":{"self":[{"href":"https:\/\/emka.web.id\/en\/wp-json\/wp\/v2\/posts\/2217","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/emka.web.id\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/emka.web.id\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/emka.web.id\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/emka.web.id\/en\/wp-json\/wp\/v2\/comments?post=2217"}],"version-history":[{"count":0,"href":"https:\/\/emka.web.id\/en\/wp-json\/wp\/v2\/posts\/2217\/revisions"}],"wp:attachment":[{"href":"https:\/\/emka.web.id\/en\/wp-json\/wp\/v2\/media?parent=2217"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/emka.web.id\/en\/wp-json\/wp\/v2\/categories?post=2217"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/emka.web.id\/en\/wp-json\/wp\/v2\/tags?post=2217"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}