Choosing Add Requested Hat in the previous step creates a new hat in the profile
and specifies that the results of subsequent questions about the script's actions
are added to the newly created hat rather than the default hat for this application.
In the next screen, Novell AppArmor displays an external program that the script
executed. You can specify that the program should run confined by the phpsys-
info hat (choose Inherit), confined by a separate profile (choose Profile), or that
it should run unconfined or without any security profile (choose Unconfined).
For the case of the Profile option, a new profile is created for the program if one
does not already exist.
NOTE: Security Considerations
Selecting Unconfined can create a significant security hole and should
be done with caution.
8a
Select Inherit for the
/bin/bash
path. This adds
/bin/bash
(accessed
by Apache) to the phpsysinfo hat profile with the necessary permissions.
8b
Click Allow.
9
The remaining questions prompt you to generate new hats and add entries to your
profile and its hats. The process of adding entries to profiles is covered in detail
in the
Section 23.1, “Adding a Profile Using the Wizard”
(page 267).
When all profiling questions are answered, click Finish to save your changes
and exit the wizard.
The following is an example phpsysinfo hat.
Profiling Your Web Applications Using ChangeHat
319
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......