Where Is the SELinux Config on Linux?
SELinux mode and policy selection live in etc selinux config, with policy files under its named subfolders.
Last updated
SELinux reads one file at boot: /etc/selinux/config. SELINUX= sets enforcing, permissive, or disabled. SELINUXTYPE= picks the policy directory, usually targeted, making /etc/selinux/targeted the policy root with its binary policy under policy/. An old symlink at /etc/sysconfig/selinux points here for compatibility.
Runtime state is separate from the file. setenforce flips modes immediately without editing anything, and sestatus reports both the file setting and the live mode. Denials land in the audit log regardless. AppArmor users switching distros: this file is the counterpart to /etc/apparmor.d, but SELinux centralizes where AppArmor spreads out.
Where Linux stores this, by platform
/etc/selinux/config
Root-owned; sestatus shows file versus live mode. Policy binaries under /etc/selinux/<type>/policy. Boot flags selinux=0 and enforcing=0 override the file.
Frequently asked questions
How do I switch SELinux to permissive mode?
Edit /etc/selinux/config is not enough on its own. Use setenforce 0 for immediate permissive mode, then edit the file for persistence across reboots. Confirm with sestatus before and after.
How do I disable SELinux persistently?
Edit the file as root, set SELINUX=disabled, and reboot. The man page notes a missing or corrupt config also disables policy loading, so keep a known-good copy before experimenting.
Notice an outdated path? Let us know.