Question 1
Q1An administrator deploys a custom web service that is configured to listen on TCP port 8080. The service fails to start, and the journalctl logs show a "Permission denied" error when trying to bind to the port. The system is running in SELinux enforcing mode. The administrator confirms that firewalld is not blocking the port. What is the correct, persistent method to allow the web service to bind to port 8080?
Show answer & explanation
Correct answer: C
The issue is that SELinux policy, by default, only allows services with the httpd_t context to bind to ports labeled http_port_t (like 80, 443, 8008, etc.). Port 8080 is typically labeled http_cache_port_t or may not have a web-related label. The correct and persistent solution is to use semanage port to add a new rule to the SELinux policy, labeling port 8080 with the http_port_t type. This allows the web service to bind to it successfully. Disabling SELinux is insecure. Using audit2allow is for cases where no appropriate label exists, but http_port_t is the correct existing label for this purpose. setsebool is for toggling booleans, not for defining port labels.