Novell LINUX ENTERPRISE DESKTOP 11 - SECURITY GUIDE 17-03-2009 Manual page 201

Hide thumbs Also See for LINUX ENTERPRISE DESKTOP 11 - SECURITY GUIDE 17-03-2009:
Table of Contents

Advertisement

aa-unconfined / unconfined
aa-unconfined detects any application running on your system that listens for
network connections and is not protected by an AppArmor profile. Refer to
"aa-unconfined—Identifying Unprotected Processes"
mation about this tool.
aa-autodep / autodep
aa-autodep creates a basic skeleton of a profile that needs to be fleshed out
before it is put to productive use. The resulting profile is loaded and put into com-
plain mode, reporting any behavior of the application that is not (yet) covered by
AppArmor rules. Refer to
(page 254) for detailed information about this tool.
aa-genprof / genprof
aa-genprof generates a basic profile and asks you to refine this profile by exe-
cuting the application, generating log events that need to be taken care of by App-
Armor policies. You are guided through a series of questions to deal with the log
events that have been triggered during the application's execution. After the profile
has been generated, it is loaded and put into enforce mode. Refer to
genprof—Generating Profiles"
aa-logprof / logprof
aa-logprof interactively scans and reviews the log entries generated by an ap-
plication that is confined by an AppArmor profile in complain mode. It assists you
in generating new entries in the profile concerned. Refer to
prof—Scanning the System Log"
tool.
aa-complain / complain
aa-complain toggles the mode of an AppArmor profile from enforce to complain.
Exceptions to rules set in a profile are logged, but the profile is not enforced. Refer
to
Section "aa-complain—Entering Complain or Learning Mode"
detailed information about this tool.
aa-enforce / enforce
aa-enforce toggles the mode of an AppArmor profile from complain to enforce.
Exceptions to rules set in a profile are logged, but not permitted—the profile is
enforced. Refer to
detailed information about this tool.
Section "aa-autodep—Creating Approximate Profiles"
(page 257) for detailed information about this tool.
(page 266) for detailed information about this
Section "aa-enforce—Entering Enforce Mode"
Section
(page 272) for detailed infor-
Section "aa-
Section "aa-log-
(page 255) for
(page 256) for
Immunizing Programs
189

Advertisement

Table of Contents
loading

This manual is also suitable for:

Suse linux enterprise desktop 11

Table of Contents