> ## Content Index
> Fetch the complete content index at: https://itsfoss.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# openSUSE Tumbleweed Ditches AppArmor for SELinux
- URL: https://itsfoss.com/news/opensuse-ditches-apparmor/
- Published: 2025-02-14T13:32:05.000Z
- Updated: 2025-02-14T13:32:05.000Z
- Description: openSUSE Tumbleweed has changed its default mandatory access control (MAC) system.
- Author: Sourav Rudra
- Tags: Development Updates, News, #Import 2025-11-08 21:15

openSUSE Tumbleweed is hands down one of the [best rolling release Linux distributions](https://itsfoss.com/best-rolling-release-distros/) out there. Many people prefer it over other distributions due to its stability and consistent updates, providing a near bleeding-edge experience.

There is another edition from the same project called openSUSE Leap, which focuses on [long-term support](https://itsfoss.com/long-term-support-lts/) and is a great option for those who prefer a more stable and laid-back distro experience.

Anyhow, an important change has been made to Tumbleweed, which mostly affects fresh installations. Let’s take a closer look. 👇

**What's Happening:** Announced on the [openSUSE Factory](https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/thread/G3W5NIY3OKRBHPHWTPYEUPSS4LKZN77N/?ref=itsfoss.com) mailing lists, upcoming snapshots of openSUSE Tumbleweed **will ship with SELinux** (*in enforcing mode*) as the default mandatory access control ([*MAC*](https://en.wikipedia.org/wiki/Mandatory%5Faccess%5Fcontrol?ref=itsfoss.com)) system on the installer, with an option to switch to AppArmor if someone prefers that.

The developers mention that they have tested the SELinux implementation both manually and automatically (via [openQA](https://open.qa/?ref=itsfoss.com)) to ensure stability and reliability.

To clarify things, a MAC system is **an essential security mechanism on Linux** (*and other platforms*) that strictly regulates access to files, processes, and system resources by enforcing a set of predefined policies.

[SELinux](https://github.com/SELinuxProject?ref=itsfoss.com) and [AppArmor](https://apparmor.net/?ref=itsfoss.com) are the most widely deployed offerings for Linux, with **SELinux being a more secure option** thanks to its system-wide enforcement instead of being app-specific like AppArmor. It's highly granular, label-based controls manage access across the entire system, mitigating potential breaches.

**What to Expect:** The Tumbleweed developers have based this on [Fedora's SELinux policy](https://github.com/fedora-selinux/selinux-policy?ref=itsfoss.com), but with some openSUSE-specific [changes](https://en.opensuse.org/Portal:SELinux/Differences%5Fto%5Ffedora%5Fpolicy?ref=itsfoss.com) to integrate it seamlessly.

Existing Leap 15.x users don't need to worry, as this change doesn't affect their installs, and users of existing AppArmor-equipped Tumbleweed installs can [migrate to SELinux](https://en.opensuse.org/Portal:SELinux/Setup?ref=itsfoss.com) if they'd like to, **but it's completely optional**.

**Via:** [Phoronix](https://www.phoronix.com/news/OpenSUSE-Tumble-Goes-SELinux?ref=itsfoss.com)

**Suggested Read** 📖

[openSUSE Leap vs Tumbleweed: What’s the Difference?openSUSE is a very popular Linux distros, especially in the enterprise world. SUSE has been around in one form or another since 1996\. During most of that time, they have only had one version. Then, in 2015, they changed things up and decided to offer two versions: Leap and Tumbleweed.![](https://itsfoss.com/content/images/icon/android-chrome-192x192-8.png)It's FOSSJohn Paul Wohlscheid![](https://itsfoss.com/content/images/thumbnail/opensuse-leap-vs-tumbleweed.png)](https://itsfoss.com/opensuse-leap-vs-tumbleweed/)