Option to disable SELinux for AL2027
When you disable SELinux, SELinux policy isn't loaded or enforced and Access Vector Cache (AVC) messages aren't logged. You lose all benefits of running SELinux.
Instead of disabling SELinux, we recommend using permissive mode. It costs only a little more to run
in permissive mode than it does to disable SELinux completely. Transitioning from permissive
mode to enforcing mode requires much less configuration than transitioning back to
enforcing mode after disabling SELinux. You can label files, and the system can track and log actions
that the active policy might have denied.
For information about how to change to permissive mode, see
Change to permissive mode.
Disable SELinux
When you disable SELinux, SELinux policy isn't loaded or enforced, and AVC messages aren't logged. You lose all benefits of running SELinux.
To disable SELinux, use the following steps.
-
Ensure that the
grubbypackage is installed.rpm -q grubbygrubby-version -
Configure your bootloader to add
selinux=0to the kernel command line.sudo grubby --update-kernel ALL --args selinux=0 -
Restart your system.
sudo reboot -
Run the
getenforcecommand to confirm that SELinux isDisabled.$getenforceDisabled
For more information about SELinux, see the SELinux Notebook