I can't find where I read this now, could somebody please tell me what I need to add/remove from the strict policy to disallow running of the setenforce command (but still allow changing enforcement mode via rebooting) ? Thanks, Todd -- fedora-selinux-list mailing list fedora-selinux-list@xxxxxxxxxx http://www.redhat.com/mailman/listinfo/fedora-selinux-list