+#
+# Adding SELinux Security Settings
+# --------------------------------
+#
+# It is a good idea to leave SELinux enabled and enforcing, particularly
+# with a web server accessible from the Internet. At a minimum the
+# following SELinux labeling should be done for Nominatim:
+
+ sudo semanage fcontext -a -t httpd_sys_content_t "$USERHOME/Nominatim/(website|lib|settings)(/.*)?"
+ sudo semanage fcontext -a -t httpd_sys_content_t "$USERHOME/build/(website|lib|settings)(/.*)?"
+ sudo semanage fcontext -a -t lib_t "$USERHOME/build/module/nominatim.so"
+ sudo restorecon -R -v $USERHOME/Nominatim
+ sudo restorecon -R -v $USERHOME/build
+
+