The rest of this chapter describes using change_hat in conjunction with Apache, to
contain web server components run using mod_perl and mod_php. Similar approaches
can be used with any application server by providing an application module similar to
the mod_apparmor described next in
Section 25.2.2, “Location and Directory Directives”
(page 323).
NOTE: For More Information
For more information, see the
change_hat
man page.
25.1 Apache ChangeHat
Novell AppArmor provides a
mod_apparmor
module (package
apache2-mod-apparmor
) for the Apache program (only included in SUSE Linux
Enterprise Server). This module makes the Apache Web server ChangeHat aware. Install
it along with Apache.
When Apache is ChangeHat aware, it checks for the following customized Novell
AppArmor security profiles in the order given for every URI request that it receives.
• URI-specific hat (for example,
^phpsysinfo/templates/classic/
images/bar_left.gif
)
•
DEFAULT_URI
•
HANDLING_UNTRUSTED_INPUT
NOTE: Apache Configuration
If you install
apache2-mod-apparmor
, make sure the module gets loaded
in Apache by executing the following command:
a2enmod apparmor
316
Security Guide
Summary of Contents for LINUX ENTERPRISE DESKTOP 11
Page 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Page 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Page 10: ......
Page 29: ...Part I Authentication...
Page 30: ......
Page 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Page 126: ......
Page 127: ...Part II Local Security...
Page 128: ......
Page 158: ......
Page 173: ...Part III Network Security...
Page 174: ......
Page 194: ......
Page 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Page 210: ......
Page 228: ......
Page 229: ...Part IV Confining Privileges with Novell AppArmor...
Page 230: ......
Page 274: ......
Page 300: ......
Page 328: ......
Page 340: ......
Page 342: ......
Page 386: ......
Page 387: ...Part V The Linux Audit Framework...
Page 388: ......