Diagnosing SELinux-related Network Service Issues

The final Troubleshooting and System Maintenance item in the
RHCE part of the Exam Prep guide is the ability to diagnose
and correct networking services problems
where SELinux
contexts are interfering with proper operation
.



In most cases, this is simpler than it looks. SELinux log
messages are stored in /var/log/messages with an avc label.
But even better, the Setroubleshoot browser can identify SELinux issues,
describe causes, and even suggest solutions. Watch it for suggested commands
such as chcon to change SELinux contexts and sesetbool to set SELinux booleans. All you need to do is open the
browser in a GUI with the sealert -b command, and browse the
most recent errors.