3.5 Updating Profiles from Log Entries
The Novell AppArmor profile wizard uses aa-logprof, the tool that scans log files and
enables you to update profiles. aa-logprof tracks messages from the Novell AppArmor
module that represent exceptions for all profiles running on your system. These excep-
tions represent the behavior of the profiled application that is outside of the profile
definition for the program. You can add the new behavior to the relevant profile by
selecting the suggested profile entry.
TIP: Support for the External Profile Repository
Similar to the Add Profile Wizard, the Update Profile Wizard also supports profile
exchange with the external repository server. For background information on
the use of the external AppArmor profile repository, refer to
Section 2.5, “Using
the External AppArmor Profile Repository”
(page 23). For details on how to
configure access and access mode to the server, check the procedure described
under
Section 3.1, “Adding a Profile Using the Wizard”
(page 29).
1
Start YaST and select Novell AppArmor > Update Profile Wizard.
Running Update Profile Wizard (aa-logprof) parses the learning mode log files.
This generates a series of questions that you must answer to guide aa-logprof to
generate the security profile. The exact procedure is the same as with creating a
44
Novell AppArmor Administration Guide