
User
’
s
Gui
de
22
ing Novell AppArmor Profiles Using the Command-line Interface
”
on
page 46.
The Command-line Interface offers access to a few tools that are not
available using the other Novell AppArmor managing methods. These
tools are:
•
complain (or learning mode):
Sets profiles into complain mode.
Set it back to enforce mode when you want the system to begin
enforcing the rules of the profiles not just logging information. For
mor
e
i
nf
or
mat
i
on
on
t
hi
s
t
ool
,
r
ef
er
t
o
“
Complain or Learning Mode
”
on page 54
•
enforce:
Sets profiles back to enforce mode and the system begins
enforcing the rules of the profiles not just logging information. For
mor
e
i
nf
or
mat
i
on
on
t
hi
s
t
ool
,
r
ef
er
t
o
“
Enforce Mode
”
on
page55
•
unconfined:
Performs a server audit to find processes that are run-
ning and listening for network connections and reports whether they
are profiled or not.
•
autodep
: Generates a profile skeleton for a program and loads it
into the Novell AppArmor module in complain mode.
Building Novell AppArmor Profiles With the YaST
GUI
The YaST GUI displays when you go to the SLES 9 menu, click
Sys-
tem
,
YaST
, then click
Novell AppArmor
.
Novell AppArmor
displays
in the YaST interface as shown below:
Note:
You can also access the YaST GUI by opening a terminal win-