
Edit
Edit the highlighted line. The new edited line appears at the bottom
of the list.
Abort
Abort aa-logprof, losing all rule changes entered so far and leaving
all profiles unmodified.
Finish
Close aa-logprof, saving all rule changes entered so far and modifying
all profiles.
Click Allow or Deny for each learning mode entry. These help build the
Novell AppArmor profile.
NOTE
The number of learning mode entries corresponds to the complex-
ity of the application.
• For
Figure 23.3: Learning Mode Exception: Defining Execute Permissions
for an Entry
: From the following options, select the one that satisfies the
request for access. For detailed information about the options available,
refer to
Section 21.7, “File Permission Access Modes”
(page 249).
Inherit
Stay in the same security profile (parent's profile).
Profile
Require a separate profile to exist for the executed program. When
selecting this option, also select whether AppArmor should sanitize
the environment when switching profiles by removing certain envi-
ronment variables that can modify the execution behavior of the child
process. Unless these variables are absolutely required to properly
execute the child process, always choose the more secure, sanitized
option.
Building and Managing Profiles with YaST
273
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......