
3
Building Novell AppArmor Profiles
This chapter explains how to build and manage Novell® AppArmor profiles. You are
ready to build Novell AppArmor profiles after you select the programs to profile. For
help with this, refer to
Chapter 2, Selecting Programs to Immunize
(page 15).
3.1 Profile Components and Syntax
This section details the syntax or makeup of Novell AppArmor profiles. An example
illustrating this syntax is presented in
Section 3.1.1, “Breaking a Novell AppArmor
Profile into Its Parts”
(page 21).
3.1.1 Breaking a Novell AppArmor Profile
into Its Parts
Novell AppArmor profile components are called Novell AppArmor rules. Currently
there are two main types of Novell AppArmor rules, path entries and capability entries.
Path entries specify what the process can access in the file system and capability entries
provide a more fine-grained control over what a confined process is allowed to do
through other system calls that require privileges. Includes are a type of meta rule or
directives that pull in path and capability entries from other files.
The easiest way of explaining what a profile consists of and how to create one is to
show the details of a sample profile. Consider, for example, the following profile for
the program
/sbin/klogd
:
Building Novell AppArmor Profiles
21
Содержание APPARMOR 1.2
Страница 1: ...Novell AppArmor Powered by Immunix Administration Guide www novell com 1 2 09 29 2005...
Страница 4: ......
Страница 14: ......
Страница 116: ......
Страница 128: ......