
In the following steps, we walk you through a demo that adds hats to an Apache profile
using YaST. In the Add Profile Wizard, the Novell AppArmor profiling utilities prompt
you to create new hats for distinct URI requests. Choosing to create a new hat allows
you to create individual profiles for each URI. This allows you to create very tight rules
for each request.
If the URI that is processed does not represent significant processing or otherwise does
not represent a significant security risk, you may safely select Use Default Hat to process
this URI in the default hat, which is the default security profile.
In the demo, we create a new hat for the URI
phpsysinfo-dev
and its subsequent
accesses. Using the profiling utilities, we delegate what is added to this new hat. The
resulting hat becomes a tight-security container that encompasses all the processing on
the server that occurs when the
phpsysinfo-dev
URI is passed to the Apache Web
server.
In this demo, we generate a profile for the application phpsysinfo (refer to
http://
phpsysinfo.sourceforge.net
for more information). The phpsysinfo-dev
package is assumed to be installed under
/srv/www/htdocs/phpsysinfo-dev/
in a clean (new) install of Novell AppArmor.
1
Once phpsysinfo-dev is installed, you are ready to add hats to the Apache profile.
From the Novell AppArmor GUI, select Add Profile Wizard.
2
In Profile to Add, enter
httpd2-prefork
.
Profiling Your Web Applications Using ChangeHat Apache
107
Summary of Contents for APPARMOR 1.2
Page 1: ...Novell AppArmor Powered by Immunix Administration Guide www novell com 1 2 09 29 2005...
Page 4: ......
Page 14: ......
Page 116: ......
Page 128: ......