{"id":2132,"date":"2021-05-30T01:08:45","date_gmt":"2021-05-30T01:08:45","guid":{"rendered":"https:\/\/dft.wiki\/?p=2132"},"modified":"2026-06-08T22:44:11","modified_gmt":"2026-06-09T02:44:11","slug":"setting-up-selinux-on-ubuntu-20-04","status":"publish","type":"post","link":"https:\/\/dft.wiki\/?p=2132","title":{"rendered":"Setting Up SELinux on Ubuntu"},"content":{"rendered":"<p>SELinux is a Linux kernel security module that adds mandatory access control (MAC) by labeling files and enforcing policies for users and groups.<\/p>\n<p>Created by Red Hat and the NSA, it comes built into CentOS and Fedora and can be installed on other Linux and Unix distributions through kernel security modules.<\/p>\n<p>Install the packages:<\/p>\n<pre>sudo apt update\r\nsudo apt install policycoreutils selinux-utils selinux-basics -y<\/pre>\n<p>Check the status and activate:<\/p>\n<pre>sestatus\r\nsudo selinux-activate\r\nsudo reboot<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2152\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2021\/05\/se03.png\" alt=\"\" width=\"747\" height=\"404\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2021\/05\/se03.png 747w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2021\/05\/se03-300x162.png 300w\" sizes=\"auto, (max-width: 747px) 100vw, 747px\" \/><\/p>\n<p>After the first reboot, the system will reboot automatically one more time.<\/p>\n<p>By default, SELinux will be in permissive mode when enabled.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2149\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2021\/05\/se01.png\" alt=\"\" width=\"419\" height=\"175\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2021\/05\/se01.png 419w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2021\/05\/se01-300x125.png 300w\" sizes=\"auto, (max-width: 419px) 100vw, 419px\" \/><\/p>\n<p>Permissive mode allows applications to access files even if they are not labeled correctly, but it logs all violations.<\/p>\n<p>Enforcing mode restricts access based on SELinux labeling policies.<\/p>\n<pre>sudo selinux-config-enforcing\r\nsestatus<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2150\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2021\/05\/se02.png\" alt=\"\" width=\"425\" height=\"175\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2021\/05\/se02.png 425w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2021\/05\/se02-300x124.png 300w\" sizes=\"auto, (max-width: 425px) 100vw, 425px\" \/><\/p>\n<p>Use the following commands to get or set the current mode:<\/p>\n<pre>getenforce\r\nsetenforce\r\nsetenforce 0<\/pre>\n<p>The mode can also be set in the configuration file:<\/p>\n<pre>sudo nano \/etc\/selinux\/config<\/pre>\n<p>Or modified directly with these commands:<\/p>\n<pre>sudo sed -i 's\/SELINUX=.*\/SELINUX=<strong>enforcing<\/strong>\/' \/etc\/selinux\/config<\/pre>\n<pre>sudo sed -i 's\/SELINUX=.*\/SELINUX=<strong>permissive<\/strong>\/' \/etc\/selinux\/config<\/pre>\n<pre>sudo sed -i 's\/SELINUX=.*\/SELINUX=<strong>disabled<\/strong>\/' \/etc\/selinux\/config<\/pre>\n<p>To see the labels assigned to files in a directory:<\/p>\n<pre>ls -Zd<\/pre>\n<p>Change a label:<\/p>\n<pre>semanage fcontext -a -t <span style=\"color: #ff0000;\"><strong>FILE_TYPE<\/strong><\/span> \"\/web\"<\/pre>\n<p>For a web server, the <strong>FILE_TYPE<\/strong> would be <span style=\"color: #ff0000;\"><strong>httpd_sys_content_t<\/strong><\/span>.<\/p>\n<p>Apply the changes:<\/p>\n<pre>restorecon -Rv \/web<\/pre>\n<p>Check the log for access violations:<\/p>\n<pre>grep AVC \/var\/log\/messages<\/pre>\n<p>AVC (Access Vector Cache) can be understood as an access violation log.<\/p>\n<p>You can also look for alerts in the same file:<\/p>\n<pre>grep sealert \/var\/log\/messages<\/pre>\n<p>Then copy and run the command for the alert you want more details on, for example:<\/p>\n<pre>sealert -l askjc1c63deb-2af3-9d23-a3247a234ab34<\/pre>\n<p>Note that newly created files inherit labels from the parent directory. Moved files, however, keep their original labels and will need to be re-labeled manually.<\/p>\n<p>A good practice is to keep the system in permissive mode first, review the logs, and apply all necessary labels for your running applications before switching to enforcing mode.<\/p>\n<p>In conclusion, SELinux requires significant effort to label the entire file system before enforcing mode can be safely enabled. Without this preparation, it will likely break many applications and possibly the system itself.<\/p>\n<hr \/>\n<p>SELinux is built into RHEL-based distributions. Installing it on a Debian-based distribution is straightforward but may cause side effects and should be done carefully.<\/p>\n<p>A native alternative for Debian-based distributions is AppArmor. It runs as a service rather than being embedded in the kernel, but offers similar security features. Read more about it at [<a href=\"https:\/\/dft.wiki\/?p=2532\">Link<\/a>].<\/p>\n<p>Seccomp is also worth looking into. It sandboxes applications to limit the impact of vulnerabilities, which is useful in Kubernetes pod\/node\/cluster environments. It uses a profile to allow or deny permissions, restricting a process to only the namespaces and system calls it needs. It is simpler than AppArmor and much simpler than SELinux, but follows the same core concept.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SELinux is a Linux kernel security module that adds mandatory access control (MAC) by labeling [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-2132","post","type-post","status-publish","format-standard","hentry","category-linux"],"_links":{"self":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/2132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2132"}],"version-history":[{"count":11,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/2132\/revisions"}],"predecessor-version":[{"id":5728,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/2132\/revisions\/5728"}],"wp:attachment":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}