[Output]
# set selinux to permissive
KernelCommandLine=!selinux=0 selinux=1 enforcing=0 audit=0

[Content]
# Secure Boot / EFI related packages for manual enrollment / verification of Secure Boot
Packages=selinux-policy,
         selinux-policy-targeted,