Hands-on Lab·Red Hat Certified System Administrator
SELinux Enforcing and Permissive Modes
The shortest SELinux objective. Two commands and one asymmetry that matters: enforcing and permissive swap instantly, and `disabled` is a one-way door that needs a reboot in each direction.
Security and SELinux Guide 55 of 67 Beginner
- OSRHEL 10.0 (Coughlan)
- Kernel6.12.0-55.9.1.el10_0
- dnf4.20.0
- Flatpak1.16.0
- TimeAbout 10 min
- Reviewed23 August 2026
Written against the versions above. **Never leave a machine permissive to make a task work.** SELinux enforcing is the state the exam machine is graded in, and switching it off is the fastest way to lose several tasks at once. Permissive is a diagnostic tool - it logs what it *would* have denied.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| RHCSA-A01 | 192.168.0.31 | RHEL 10.0 (Coughlan) | Practice node (graded) - spare /dev/sda | 2 Core | 4 GB | 50 GB + 15 GB |
Before you start
- A sudo-capable account.
- The session switches to permissive and back, and finishes enforcing.
-
The three states
-
Switching at runtime