OpenSUSE :: Set Up Novell Apparmor?
Feb 19, 2010Set up Novell Apparmor? how to do it.
View 2 RepliesSet up Novell Apparmor? how to do it.
View 2 Repliesrecently I am interesting at apparmor, and I have read some docs of it, but I have a question that how to protect apparmor itself? I mean only if gained root privilege then stop apparmor service, all the protection will no longer effect, if I hiding or remove root user then how to remodify profiles if needed that because have not enough privilege.
Is there apparmor maillist? maybe you can email me: <email removed for obvious reasons>
Here's my problem: Clean OpenSUSE 11.3 64 bit installation using default options into a Virtualbox virtual machine for pre-production testing. I want to check whether AppArmor is enabled, so I enter YaST -> AppArmor Control Panel.
This has a check box named 'Enable AppArmor' which is by default un-checked. I check this box, and then click 'Done'. This takes me back to YaST and I would assume AppArmor has now been enabled. However, when I return to AppArmor Control Panel the check box is deselected again.
depending on reading some apparmor docs, I know that apparmor read logs to determine what profile a program will be, that means a profile only can be built when the program have been exec at least a time, or we already how will be executed of a specific program. but if a hack inserts a bad-program such as a back door or virus what should never be executed any time, and at the same time we don't know what's the consequence will happen due to the behaviors of a bad-program. therefore, how could apparmor do to prevent these situations? Can apparmor confine every thing what under a specific directory by default? because use: aa-autodep /path/to/restrict/* is 'complain' by default and everything are allowed, can apparmor deny everything by default?
View 2 Replies View RelatedEmail alerting from Apparmor profile to gmail is possible, but email cannot be forwarded to other email address
View 1 Replies View RelatedIn case this is a thread in the wrong section please move it to the right one. Following situation applies.I am using openSUSE 11.1 with modified kernel. Code:# uname -aLinux linux-2c5j 3.0.4-41-desktop #1 SMP PREEMPT Sun Sep 4 18:51:01 CEST 2011 i686 i686 i386 GNU/Linux The compilation did run flawlessly with the SAKC script.However the module apparmor does not load. Infact:Code:# modprobe apparmorFATAL: Module apparmor not found. I understand that I have to recompile the module, right? There I have the first question: wasn't the apparmor module accepted into the kernel (and therefore should be already compiled and available with the normal kernel compile)? Or is this wrong. How can I recompile the apparmor module for my new kernel.
View 1 Replies View RelatedIs there a particular app listed as apparmor, or is it a series of separate programs that act as a whole? if the latter, which programs are these. i just got really lucky with my installation of 11.2, and I'm trying to confirm my success.
View 9 Replies View RelatedIs recommended to create a profile in apparmor for applications like amule, firefox, thunderbird, amsn ....?
View 7 Replies View RelatedDoes it make sense to run sshd confined/protected by apparmor? I get tons of attack/hack attempts on my ssh port daily, I created a white list on my firewall to specify the IP addresses that can ssh into my network. I was also thinking of activating the sshd profile in apparmor for some added protection?
View 5 Replies View Relatedprohibit execution of any program include shell command, only be profiled program could be executed, can apparmor do that?
View 5 Replies View RelatedCurrently the Apparmor program has the notification logs saved to /etc/apparmor/notify.cfg, however, when I try to save the notification after putting my email address in, I get an error saying "Configuration failed for the following operations: Unable to write config changes to /etc/apparmor/notify.cfg"looking inside the folder, I do not see any file named "notify.cfg" BUT I do see so files called reports.conf, logprof.conf, and reports.crontab. I am guessing that the program is asking to save the notification changes to a file that does not exist and in fact one of those three files are the proper ones to use. Well if that is the case then how would I go about fixing this error?
View 4 Replies View RelatedI have just reinstalled OS 11.2 but this time the 64bit system variant. I installed the real-time kernel and saw that the apparmor module reported an error and wasn't loaded. I have never looked into apparmor and only knows it has something to do with security, and thus I wonder if it is important to do something with this issue? I plan to use the kernel-rt and have more or less always used a variant of this kernel flavour, often self built. Though I can not recall having seen that error before and I have not used a 64bit system before
View 2 Replies View RelatedI have a box already has openSuse 11 32bits installed. I want to replace it with openSuse 11 64 bits. When I insert the openSuse 11 64 bits CD, I got error message "this is a 32 bit computer. Can not use 64 bit software". so How do I wipe out the old OS (32 bits), and install new OS (64 bits)?
View 7 Replies View RelatedTrying to install the Novell iprint client but got the following error message:
My system specifications are as follows:
When trying to install Novell client (novell-client-2.0-sp2-sle11-i586.iso) on my 11.2 box, I get the following error: "Problem: nothing provides libbfd-2.19.so needed by novell-xtier-base-3.1.6-12.i586". The libbfd library is provided by binutils. I have binutils-2.19.51-10.26.4.i586 installed, and it provides /usr/lib/libbfd-2.19.51.20090527-10.26.4.so. I made symlinks (/lib/libbfd-2.19.so and /usr/lib/libbfd-2.19.so
View 9 Replies View RelatedIs it possible to get the novell Client work on openSUSE 11.3(KDE)?
View 1 Replies View RelatedI am using kde and can't get rid of a gnome patch. Problem won't go away in updater applet tray or yast online update.
View 2 Replies View RelatedWhere can i request a free openSUSE cd's from online.I could not Download Because my Internet connection speed is very low.
View 1 Replies View RelatedI use Linux with a lot of pleasure almost 6 years... after installing Ubuntu 10.04 Itried to install openSuSE on with Ubuntu prepared partitions, 20GB for / and 120 for /home. I have tried 4 times to install SuSE, but I have each time same problem. Suse installer shows instead 20 and 120GB partitions 16 and 104 GB and insallation was failed with message that PC probably was attacked. Before was installed excellent worked OpenSuSE 10.3. I have no idea. It's PC with AMD 3200 64-bit, 1GB DDR, Nvidia7300SE.
View 3 Replies View RelatedFor the past several years I have grown fond of ver. 11.0...I have installed many programs with that verison. I have checked out the Live ver. of 11.3, and I like it allot but I'm wondering if I can some how check the software available for 11.3 to see if the same program/s are available with ver. 11.3. In other words can I run the Live CD, click on the Yast package installer and look for the same programs I have with ver. 11.0 ?
View 1 Replies View RelatedWith OpenSUSE 10.3 iPrint was working. I was printing to a Novell iPrint-server and had no problems at all. Now i upgrade til OpenSUSE11.1 and now iPrint does not work at all. I downloaded the lates iPrint Client that was released 13.januar 2009 and tried to install. It claims i miss "libglitz.so.1". I searche for this file in Yast and find Glitz-i586 Installed it and now iPrint Client did install witout any errors. Now i try to install an iPrint-printer that have a Linux-driver attached. Firefox crash everytime i try to install this printer. I tried both as normal user and as root but with same result. I know the normal respons is "Novell doesnt support OpenSUSE but only SLED". I dont like SLED because its not near as good as OpenSUSE. SLED does not support any multimedia and i had several unresolveable problems with it. Novell develop Novell Client for OpenSUSE, so why not iPrint Client?
View 4 Replies View RelatedHow can I allow root logins using kde gui 4.5.3 on opensuse 11.3 ? Currently the gui says "root logons are not allowed" Rpms installed see listing [1]
[1]
# rpm -qa | grep -i kde |sort
NetworkManager-kde4-0.9.svn1184295-5.2.x86_64
NetworkManager-kde4-libs-0.9.svn1184295-5.2.x86_64
NetworkManager-openvpn-kde4-0.9.svn1184295-5.2.x86_64
NetworkManager-pptp-kde4-0.9.svn1184295-5.2.x86_64
[Code].....
I am using openSUSE 10.3 and the pc is DELL Optiplex 780. The network devices is not supported by openSUSE 10.3 but I may have found it's module. But I can't "MAKE INSTALL" it as my installation does not have MAKE command.
I have selected "Install All" during my installation. Linux version is 2.6.22.5-31-default.
What is the package name for the MAKE command? So that I can find it so that I can install it into my openSUSE 10.3?
So I have tried to install from LiveCD and from a LiveUSB stick. Installation goes fine till I get to CUPS daemon. Then I get the wait 30 seconds for CUPS to activate, that never works. Then it pops up with a wait one minute for CUPS to become available. Then it finishes the installation and restarts the system and I get previous installation has failed would you like to retry? It does this over and over again till I get an error with my user name and the mouse and keyboard quit working. I have tried in Failsafe mode, No ACPI, etc. and nothing seems to work. I don't know if it matters but I have an Asus mobo M4A785-M and an AMD Athlon II x3 440 chip. I am just ready to switch to Ubuntu
View 14 Replies View RelatedI have just installed opensuse 11.3 on my box and it refuses to shut down. It shows a tty screen with the message "power down" but wont power off. After searching the web I found no solution until I compared the "halt" scripts of versions 11.3 and 11.2 (they are located in /etc/init.d). Both scripts differ only by a couple of lines that make reference to raid devices. As I am not using any RAID array in my BIOS, I copied my halt script (version 11.2) on top of the version 11.3 halt script and my box started to shut down and power off nicely! At least for me it worked!
View 28 Replies View RelatedI've had this issue since OpenSUSE 10.5 and Firefox 2.x. Now I'm on OpenSUSE 11.2 and Firefox 3.5.6. Here's the issue: I log into various sites to get my bank statements, utility bills, etc. They are all in PDF, and they open up acrobat reader and from there I save the bill as a permanent record. The first one I open opens fine. Subsequent sessions with subsequent providers (banks, whatever) opens up a new window as if to show me the PDF, but no PDF is there. Status on the window shows "done." No error messages. I have to shut firefox down, restart, log in again, and then it downloads fine. It's getting annoying.
View 2 Replies View RelatedI'm new to XEN, but I have a great book ("The Book of XEN") which is helping me get started. I have learned to use "virt-manager" to create a new VM, I have my dom0 running, and I want to add a domU, and I want it to be Kubuntu 9.10. But every attempt to use a Kubuntu install CD results in "not bootable" errors for the install disk. I have booted from the CD, so I know it's not corrupt. I also tried using "xm" manually to create the vm with the following configuration with the same result as in virt-manager:
name = "mx8711kbu"
maxmem = 768
memory = 768
vcpus = 1
bootloader = "/usr/bin/pygrub"
on_poweroff = "destroy"
on_reboot = "restart"
on_crash = "restart"
[Code]...
Am I stuck, or is there a way to do this? I do not have hardware virtualization?. That's not an option. I did a lot of searching on the web without much luck before posting this. I know this is not a new problem. I've found references to it.
today I had (once again) a bad experience with the Openoffice.org version shipped with OpenSuSe 11.2 (in this case OpenOffice.org 3.2.1 OOO320m19 (Build:9505) ooo-build 3.2.1.3) which is labeled stable. In calc, double borders (format --> cells --> borders 1,1pt) disappear after saving and reopening. After almost getting crazy and reactually onlyformatting the same spreadsheet far to many times, I realized I was not too stupid hitting the save button and decided to install the plain vanilla version (as I had done on a previous version on my laptop due to another novell edition bug I cannot recall.) Luckily the plain vanilla version has not this bug. However, since I like some of the features the novell edition offers (namely colored tabs and .xlsx export support) and I generally prefer installing software through repositories where possible, and of course because it is my duty as an opensource user. I would like to know were to report a bug that is specific to the version of a program shipped with OpenSuse.
View 2 Replies View RelatedI have a Toshiba Satellite Pro laptop with the following specifications:Proccesor: Intel Core i3 350M / 2.26 GHzRAM: 4GB DDR3Hard Disk: 320GB SATA 5400rpmArchitecture: x86_64The computer has already Windows 7 installed on the C drive whereas there's a D hidden drive with a copy of the recovery image.I'm having trouble to install openSuSE 11.3 as follows:I boot the system with the DVD in its drive. After the welcome screen the process stops
using the typical GUI interface and runs a less graphical one. It is at this point where a
window pops up with a request:"Make sure that CD number 1 is in your drive"I press OK but the window keeps popping up. Frustrated I hit Back and a red window comes up with the message:"No repository found."I cannot go any further than this point
Can anyone provide a guide on how to install cuda drives for opensuse 11.2 64 bit?
View 1 Replies View Related