My Profile Photo

Sheogorath's Blog

Depending on the time of the day a friend, a colleague, a wise guy. The beauty of the world is its sense of humor to show humans their way by letting them search their own.

Cover image for this blog post

SELinux kernel flags

Today I learned that SELinux can be disabled in two ways during boot. Besides enforcing=0 there is also selinux=0. The former will obviously set SELinux in permissive mode but still label all new files properly. While the latter will disable SELinux entirely and therefore break your system by labelling all newly created files with default_t on next SELinux-enabled reboot.

I learned this from this talk about SELinux I watched today.