SELinux adds policy-based controls beyond traditional Linux ownership and permissions. This hands-on course teaches you to inspect that policy state, recognize common mismatches, and investigate a service denial without treating SELinux itself as the problem.
You will compare enforcing and permissive modes, trace file labels, repair incorrect contexts, enable a supported policy boolean, and read AVC audit evidence. In the final challenge, you diagnose why Nginx cannot bind to port 8088, generate and install a focused policy module from the denial, and verify the service response.
What You Will Learn
- Inspect SELinux status and distinguish runtime mode from boot-time configuration
- Read file security contexts and identify the type field used by policy
- Explain why moved files can retain an unsuitable label for their new location
- Compare current and expected contexts and repair individual or recursive label mismatches with
restorecon - Find, enable persistently, and verify a service-specific SELinux boolean
- Locate Nginx AVC denials and interpret a blocked
name_bindoperation - Use
audit2allowto explain a denial and generate a custom policy module - Install a generated module and verify Nginx on a nonstandard port
Who This Course Is For
This intermediate course is for Linux administrators, DevOps practitioners, and security learners who understand normal Unix permissions and want a practical introduction to SELinux operations and troubleshooting.
Prerequisites: Comfort with the Linux shell, files and permissions, sudo, systemctl, text editing, ports, and basic web-service concepts. No prior policy-authoring experience is required.
Learning environment: A Linux terminal prepared with SELinux commands, policy data, audit evidence, Nginx, and administrative privileges. Kernel or container restrictions may prevent a real enforcement-mode transition, so some denials can be simulated while the same inspection and remediation commands are practiced.
Frequently Asked Questions
Will this course teach me to disable SELinux when an application fails?
No. Permissive mode is used as a temporary diagnostic concept. The course emphasizes inspecting labels, supported booleans, and audit records before making a targeted policy change.
What kinds of SELinux fixes do I practice?
You restore policy-defined file contexts, persistently enable httpd_can_network_connect, and generate and install a small policy module from an Nginx port-binding denial. The course does not provide broad SELinux policy-language coverage.
Is audit2allow presented as the answer to every denial?
No. You learn to inspect what it proposes and to consider whether a label, boolean, or standard policy adjustment is more appropriate. The final challenge specifically requires a generated module; alternatives such as managing port types with semanage port are outside this course’s hands-on scope.





