I remember that once apon a time there was a boolean (or at least a setting in system-config-selinux) that would block root from using setenforce to change from enforcing to permissive mode. I can't seem to find it now on F17. I haven't figured out the correct combo to find this via google. I tested the secure_mode boolean, but that didn't appear to work. Nothing else in the list looked like it would block changing to permisive mode. Is this setting gone now? If not can someone point me to what it is or documentation about it? Thanks. -- selinux mailing list selinux@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/selinux