[root@localhost selinux]# ls /selinux/
access commit_pending_bools disable mls user
avc/ compat_net enforce null
booleans/ context initial_contexts/ policyvers
checkreqprot create load reject_unknown
class/ deny_unknown member relabel
cat /etc/selinux/config 结果如下:
# This file controls the state of SELinux on the system.
# SELINUX= can take one of these three values:
# enforcing - SELinux security policy is enforced.
# permissive - SELinux prints warnings instead of enforcing.
# disabled - No SELinux policy is loaded.
#SELINUX=permissive
SELINUX=enforcing
# SELINUXTYPE= can take one of these two values:
# targeted - Targeted processes are protected,
# mls - Multi Level Security protection.
SELINUXTYPE=targeted
# SETLOCALDEFS= Check local definition changes
SETLOCALDEFS=0