CentOS/RHEL guy here, and I have to say, SELinux FTW. So many times I've been frustrated and annoyed when people's first reaction is 'disable it' when they hit some problem (almost always due to using stuff in a wrong or nonstandard way)* instead of spending 5 min to get it working and having far more security.
* (That, and custom programs that use perversely wrong paths, e.g. web content in /home, logs in the application directory, etc.)
* (That, and custom programs that use perversely wrong paths, e.g. web content in /home, logs in the application directory, etc.)