
rcsubdomain restart
Causes SubDomain module to rescan the profiles usually found in
/etc/
subdomain.d
without unconfining running processes, adding new profiles, and
removing any profiles that had been deleted from
/etc/subdomain.d
.
rcsubdomain kill
Unconditionally removes the SubDomain module from the kernel. This is unsafe,
because unloading modules from the Linux kernel is unsafe. This command is
provided only for debugging and emergencies when the module might have to be
removed.
NOTE
Novell AppArmor is a powerful access control system and it is possible to
lock yourself out of your own machine to the point where you have to
boot the machine from rescue media (such as CD 1 of SUSE Linux) to regain
control.
To prevent such a problem, always ensure that you have a running, uncon-
fined, root login on the machine being configured when you restart the
SubDomain module. If you damage your system to the point where logins
are no longer possible (for example, by breaking the profile associated
with the SSH daemon), you can repair the damage using your running root
prompt and restarting the SubDomain module.
3.4.2 Building Novell AppArmor Profiles
The SubDomain module profile definitions are stored in the directory
/etc/
subdomain.d/
as plain text files.
WARNING
All files in the
/etc/subdomain.d/
directory are interpreted as profiles and
are loaded as such. Renaming files in that directory is not an effective way of
preventing profiles from being loaded. You must remove profiles from this di-
rectory to manage them effectively.
Building Novell AppArmor Profiles
51
Summary of Contents for APPARMOR 1.2
Page 1: ...Novell AppArmor Powered by Immunix Administration Guide www novell com 1 2 09 29 2005...
Page 4: ......
Page 14: ......
Page 116: ......
Page 128: ......