

SELinux(Security-Enhanced Linux)是一种基于强制访问控制(MAC)的Linux内核安全模块,它提供了一种更加灵活和强大的安全策略,通过限制进程和文件的权限来保护系统免受攻击,SELinux最初是由美国国家安全局(NSA)开发的,后来成为Linux发行版的标准安全模块之一。














SELinux state:SELinux的状态,如Enabled(已启用)、Disabled(已禁用)等。

SELinux type:SELinux的安全上下文类型,如targeted(目标模式)、minimum(最小模式)等。

SELinux domain path:SELinux的安全域路径,用于区分不同的安全区域。

SELinux root directory:SELinux的根目录,存储安全策略相关的配置文件。

SELinux version:SELinux的版本号。





sudo cp /etc/selinux/config /etc/selinux/config.bak


sudo vi /etc/selinux/config





This file controls the state of SELinux on the system.
SELINUX= can take one of these three values:
    enforcing SELinux security policy is enforced.
    permissive SELinux prints warnings instead of enforcing.
    disabled No SELinux policy is loaded.
SELINUXTYPE= can take one of three values: targeted, minimum, generalized.
    targeted Targeted processes are protected, while non-targeted processes are not.
    minimum Modification of targeted policy. Only selected processes are protected.  Ignored if SELINUXTYPE=targeted.
    generalized Generalized process labeling. All processes are labeled with the same level of priority. Ignored if SELINUXTYPE=targeted or minimum.
