Setting Up AppArmor Profiles

AppArmor is the major open-source alternative to SELinux. Both provide mandatory access control for files, directories, and users. Some administrators believe that AppArmor policies are easier to create and configure. However, the protection afforded by AppArmor depends on the policies you create for the services and critical files on the local system.

If you’ve installed AppArmor and SELinux packages on the same system, be aware that these mandatory access control systems are not compatible. Because AppArmor drivers are integrated into current Linux kernels, you can disable AppArmor with the following entry on the kernel command line in the bootloader:

Basic AppArmor Configuration

AppArmor has four basic modes: ...

Get Security Strategies in Linux Platforms and Applications, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.