
5.1 Apache ChangeHat
Novell AppArmor provides a
mod_change_hat
module for the Apache program.
The
mod_change_hat
module works on your SUSE Linux to make the Apache web
server become “ChangeHat aware.” It is installed if Apache is on your system.
When Apache is ChangeHat-aware, it checks for the following customized Novell
AppArmor security profiles in the order given for every URI request that it receives.
• URI-specific hat (for example,
^phpsysinfo-dev/templates/classic/
images/bar_left.gif
)
•
DEFAULT_URI
•
HANDLING_UNTRUSTED_INPUT
If you have the required Apache 2 on your system, the
mod_change_hat
module is
automatically installed with Novell AppArmor as well as added to the Apache configu-
ration. Apache 1.3 is not supported.
NOTE
If you install
mod_change_hat
without Novell AppArmor, you need to make
sure the Apache load module has a command in the config file that loads the
mod_change_hat
module by adding the following line to your Apache con-
figuration file:
LoadModule change_hat_module modules/mod_change_hat.so
5.1.1 Tools for Managing ChangeHat-Aware
Applications
As with most of the Novell AppArmor tools, you can use two methods for managing
ChangeHat, YaST or the command line interface. Manage ChangeHat-aware applications
much more flexibly at the command line, but the process is also more complicated.
Both methods allow you to manage the hats for your application and populate them
with profile entries.
106
Summary of Contents for APPARMOR 1.2
Page 1: ...Novell AppArmor Powered by Immunix Administration Guide www novell com 1 2 09 29 2005...
Page 4: ......
Page 14: ......
Page 116: ......
Page 128: ......