
SELinux (AlmaLinux, Rocky and others in the Red Hat family) and AppArmor (Ubuntu and Debian) are security layers that deny actions even to whoever has the right permissions. If a service gets “Permission denied” and the owner and chmod are right, this is the suspect. You find out by switching the module to warning mode for a moment and reading what was denied; you fix it with the right rule, not by turning the protection off. On an unmanaged VPS this is yours to do.
Which one you have
| SELinux | AppArmor | |
| Where it usually ships | AlmaLinux, Rocky, other Red Hat family | Ubuntu and Debian |
| See the state | getenforce or sestatus | sudo aa-status |
| See what was denied | sudo ausearch -m avc -ts recent (needs auditd) or the system log | The kernel log: sudo journalctl -k | grep -i apparmor look for “DENIED” |
| Rehearse without blocking | sudo setenforce 0 (permissive mode, until the next boot) | sudo aa-complain /path/to/profile (from the apparmor-utils package) |
| Protect again | sudo setenforce 1 | sudo aa-enforce /path/to/profile |
Step by step
|
|
|
|
|
The most common cases
| Situation | Fix (SELinux) | Fix (AppArmor) |
| The web server will not read a folder outside /var/www | sudo semanage fcontext -a -t httpd_sys_content_t "/srv/site(/.*)?" and sudo restorecon -Rv /srv/site (semanage comes from the policycoreutils-python-utils package) | Edit the program’s profile in /etc/apparmor.d/ to allow the folder and reload with sudo systemctl reload apparmor |
| The web server (as a proxy) cannot connect to the application | sudo setsebool -P httpd_can_network_connect 1 | Rare; it is a specific profile. |
| A service wants to listen on a new port (for example SSH on another port) | sudo semanage port -a -t ssh_port_t -p tcp 2222 (2222 is an example; for the web server, http_port_t) | Usually not needed. |
| Copied or moved files carry the wrong label | sudo restorecon -Rv /folder | Does not apply. |
| Turning SELinux off for good is the answer you regret. SELINUX=disabled in /etc/selinux/config removes a protection that defends the server from a flaw in an application. The same goes for stopping AppArmor. Always prefer the smallest rule; use permissive mode only to diagnose, and briefly. |
| Changing a label or profile without understanding can open what should stay closed. If you do not understand the denied line, copy it and look it up in the distribution’s documentation before applying anything. Depending on your system, package and tool names may vary. |
| Before blaming SELinux or AppArmor, check the basics: is the service running? is the port open in the firewall (ports and firewall)? does the file exist? Most “Permission denied” cases are plain permissions. |
|
Did the server become unreachable over SSH after touching these protections? The panel console gets you in without the network: tell us what you did. Open a support ticket |
|
SEE ALSO File permissions on a Linux VPS A service will not start: reading systemctl status |
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.59/mo (3-year plan, with coupon) See plans |
- 0 Users Found This Useful











