Linux sestatus command
sestatusis a command-line tool in Linux systems used to view the current status of SELinux (Security-Enhanced Linux). SELinux is a mandatory access control (MAC) security mechanism developed by the U.S. National Security Agency (NSA), providing an additional security layer for Linux systems.
Command Syntax
sestatus [选项]
Common Options
| Option | Description |
|---|---|
-v |
Display detailed output, including context information for processes and files |
-b |
Display the currently loaded policy booleans (rule switches) |
Command Output Explanation
Runsestatuscommand, the typical output is as follows:
Examples
SELinuxfs mount: /sys/fs/selinux
SELinux root directory: /etc/selinux
Loaded policy name: targeted
Current mode: enforcing
Mode from config file: enforcing
Policy MLS status: enabled
Policy deny_unknown status: allowed
Memory protection checking: actual (secure)
Max kernel policy version: 33
Key Field Descriptions
-
SELinux status
enabled: SELinux is enableddisabled: SELinux is disabled
-
Current mode
enforcing: Enforcing security policypermissive: Only logs violations but does not blockdisabled: Completely disabled
-
Loaded policy name
targeted: Default policy, only protects specific servicesmls: Multi-level security policy (more strict)minimum: Minimum policy
Practical Usage Examples
Example 1: Check SELinux Basic Status
$ sestatus
This is the most basic usage, quickly checking whether SELinux is enabled and its running mode.
Example 2: View Detailed Context Information
$ sestatus -v
The output will include context information for processes and files, for example:
Example
Current context: unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
Init context: system_u:system_r:init_t:s0
...
File contexts:
Controlling terminal: unconfined_u:object_r:user_devpts_t:s0
...
Example 3: View Current Policy Booleans
$ sestatus -b
The output will display the status of all configurable policy rule switches, for example:
Example
abrt_anon_write off
abrt_handle_event off
...
httpd_can_network_connect off
...
Common Troubleshooting
Problem 1: SELinux Blocks Normal Operations
Solution:
- First confirm whether the problem is caused by SELinux:
grep "avc:" /var/log/audit/audit.log
- If so, you can temporarily set it to permissive mode for testing:
sudo setenforce 0
- The permanent solution is to adjust the SELinux policy or modify the file context
Problem 2: sestatus Shows SELinux Is Disabled
Possible Causes:
- SELinux was disabled at system startup
/etc/selinux/configIn the file, the setting is configuredSELINUX=disabled
Solution:
- Edit
/etc/selinux/configfile - Modify
SELINUX=enforcingorSELINUX=permissive - Reboot the system
Best Practices
-
Production Environment Recommendations
- Keep SELinux in
enforcingmode to obtain maximum security - Do not easily disable SELinux; instead, learn how to configure it correctly
- Keep SELinux in
-
Troubleshooting Steps
- First use
sestatusto check status - View
/var/log/audit/audit.logto get detailed denial information - Use
audit2allowto generate custom policy modules
- First use
-
Policy Adjustment
- Prefer to use
setseboolto adjust booleans - Next consider modifying file contexts (
chcon) - Finally, consider creating custom policy modules
- Prefer to use
Summary
sestatusThe sestatus command is the first-line tool for managing SELinux systems. Through it, you can quickly understand the security state of the system. Mastering the use of this command can help system administrators better maintain the security of Linux systems, and quickly locate the cause when permission problems occur.
Other Extensions
Linux Command Reference