SELinux Modes Explained: setenforce, getenforce and Troubleshooting
SELinux is mandatory access control for Linux. Standard Linux permissions are discretionary — the owner of a file decides who may read it. SELinux adds a policy layer that the owner cannot override, enforced by the kernel against every process. The practical consequence, and the reason it appears on the exam, is that a process can be denied access to a file its Unix permissions clearly allow. The three modes Mode Behaviour Enforcing Policy is applied; violations are blocked and logged Permissive Policy is not applied; violations are logged only Disabled SELinux is off; nothing is enforced or logged Permissive is the diagnostic mode. It lets you confirm whether SELinux is the cause of a problem without leaving the system unprotected, and it records every denial that would have occurred — so you can fix all of them at once rather than one reboot at a time. Checking and changing the mode getenforce prints the current mode. sestatus gives fuller detail, including the mode from...