The questions fall into two categories:
• A resource is requested by a profiled program that is not in the profile
(see
Figure 23.2, “Learning Mode Exception: Controlling Access to Spe-
cific Resources”
(page 270)). Allow or deny access to a specific resource.
• A program is executed by the profiled program and the security domain
transition has not been defined (see
Figure 23.3, “Learning Mode Excep-
tion: Defining Execute Permissions for an Entry”
(page 271)). Define ex-
ecute permissions for an entry.
Each of these cases results in a series of questions that you must answer to
add the resource to the profile or to add the program to the profile. For an ex-
ample of each case, see
Figure 23.2, “Learning Mode Exception: Controlling
Access to Specific Resources”
(page 270) and
Figure 23.3, “Learning Mode
Exception: Defining Execute Permissions for an Entry”
(page 271). Subsequent
steps describe your options in answering these questions.
NOTE: Varying Processing Options
Depending on the type of entry processed, the available options vary.
Figure 23.2
Learning Mode Exception: Controlling Access to Specific Resources
270
Security Guide
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......