To change the status of Novell AppArmor, continue as described in
Section 23.6.1,
“Changing Novell AppArmor Status”
(page 284). To change the mode of individual
profiles, continue as described in
Section 23.6.2, “Changing the Mode of Individual
Profiles”
(page 284). To configure security event notification, continue as described in
Section 27.2, “Configuring Security Event Notification”
(page 330).
23.6.1 Changing Novell AppArmor Status
When you change the status of AppArmor, set it to enabled or disabled. When AppArmor
is enabled, it is installed, running, and enforcing the AppArmor security policies.
1
Start YaST and select Novell AppArmor > AppArmor Control Panel.
2
Enable AppArmor by checking Enable AppArmor or disable AppArmor by des-
electing it.
3
Click Done in the AppArmor Configuration window.
4
Click File > Quit in the YaST Control Center.
23.6.2 Changing the Mode of Individual
Profiles
AppArmor can apply profiles in two different modes. In complain or learning mode,
violations of AppArmor profile rules, such as the profiled program accessing files not
permitted by the profile, are detected. The violations are permitted, but also logged.
This mode is convenient for developing profiles and is used by the AppArmor tools for
generating profiles. Loading a profile in enforce mode enforces the policy defined in
the profile and reports policy violation attempts to syslogd.
284
Security Guide
Summary of Contents for LINUX ENTERPRISE DESKTOP 11
Page 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Page 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Page 10: ......
Page 29: ...Part I Authentication...
Page 30: ......
Page 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Page 126: ......
Page 127: ...Part II Local Security...
Page 128: ......
Page 158: ......
Page 173: ...Part III Network Security...
Page 174: ......
Page 194: ......
Page 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Page 210: ......
Page 228: ......
Page 229: ...Part IV Confining Privileges with Novell AppArmor...
Page 230: ......
Page 274: ......
Page 300: ......
Page 328: ......
Page 340: ......
Page 342: ......
Page 386: ......
Page 387: ...Part V The Linux Audit Framework...
Page 388: ......