Novell LINUX ENTERPRISE SERVER 10 - INSTALLATION AND ADMINISTRATION 11-05-2007 Installation Manual page 892

Table of Contents

Advertisement

1 As root, let AppArmor create a rough outline of the application's profile by
2 Run the full range of the application's actions to let AppArmor get a very specific
3 Let AppArmor analyze the log files generated in
4 Depending on the complexity of your application, it might be necessary to repeat
5 Once all access permissions are set, your profile is set to enforce mode. The
874
Installation and Administration
running aa-genprof programname
or
Outline the basic profile by running YaST > Novell AppArmor > Add Profile
Wizard and specifying the complete path of the application to profile.
A basic profile is outlined and AppArmor is put into learning mode, which means
that it logs any activity of the program you are executing but does not yet restrict
it.
picture of its activities.
typing S in aa-genprof.
or
Analyze the logs by clicking Scan system log for AppArmor events in the Add
Profile Wizard and following the instructions given in the wizard until the profile
is completed.
AppArmor scans the logs it recorded during the application's run and asks you
to set the access rights for each event that was logged. Either set them for each
file or use globbing.
Step 2
(page 874) and
the confined conditions, and process any new log events. To properly confine
the full range of an application's capabilities, you might be required to repeat this
procedure often.
profile is applied and AppArmor restricts the application according to the profile
just created.
If you started aa-genprof on an application that had an existing profile that was
in complain mode, this profile remains in learning mode upon exit of this learning
cycle. For more information about changing the mode of a profile, refer to Section
Step 3
(page 874). Confine the application, exercise it under
Step 2
(page 874) by running

Advertisement

Table of Contents
loading

This manual is also suitable for:

Suse linux enterprise server 10

Table of Contents