Jump to contentJump to page navigation: previous page [access key p]/next page [access key n]
Applies to SUSE Linux Enterprise Server 11 SP4

19 Getting Started

Prepare a successful deployment of AppArmor on your system by carefully considering the following items:

  1. Determine the applications to profile. Read more on this in Section 19.3, “Choosing the Applications to Profile”.

  2. Build the needed profiles as roughly outlined in Section 19.4, “Building and Modifying Profiles”. Check the results and adjust the profiles when necessary.

  3. Keep track of what is happening on your system by running AppArmor reports and dealing with security events. Refer to Section 19.5, “Configuring AppArmor Event Notification and Reports”.

  4. Update your profiles whenever your environment changes or you need to react to security events logged by AppArmor's reporting tool. Refer to Section 19.6, “Updating Your Profiles”.

19.1 Installing AppArmor

AppArmor is installed and running on any installation of SUSE® Linux Enterprise Server by default, regardless of what patterns are installed. The packages listed below are needed for a fully-functional instance of AppArmor

  • apparmor-docs

  • apparmor-parser

  • apparmor-profiles

  • apparmor-utils

  • audit

  • libapparmor1

  • perl-libapparmor

  • yast2-apparmor

19.2 Enabling and Disabling AppArmor

AppArmor is configured to run by default on any fresh installation of SUSE Linux Enterprise Server. There are two ways of toggling the status of AppArmor:

Using YaST System Services (Runlevel)

Disable or enable AppArmor by removing or adding its boot script to the sequence of scripts executed on system boot. Status changes are applied on reboot.

Using AppArmor Control Panel

Toggle the status of AppArmor in a running system by switching it off or on using the YaST AppArmor Control Panel. Changes made here are applied instantaneously. The Control Panel triggers a stop or start event for AppArmor and removes or adds its boot script in the system's boot sequence.

To disable AppArmor permanently (by removing it from the sequence of scripts executed on system boot) proceed as follows:

  1. Start YaST.

  2. Select System › System Services (Runlevel).

  3. Select Expert Mode.

  4. Select boot.apparmor and click Set/Reset › Disable the service.

  5. Exit the YaST Runlevel tool with Finish.

AppArmor will not be initialized on reboot, and stays inactive until you reenable it. Reenabling a service using the YaST Runlevel tool is similar to disabling it.

Toggle the status of AppArmor in a running system by using the AppArmor Control Panel. These changes take effect as soon as you apply them and survive a reboot of the system. To toggle AppArmor's status, proceed as follows:

  1. Start YaST.

  2. Select AppArmor › AppArmor Control Panel.

  3. Select Enable AppArmor. To disable AppArmor, uncheck this option.

  4. Exit the AppArmor Control Panel with Done.

19.3 Choosing the Applications to Profile

You only need to protect the programs that are exposed to attacks in your particular setup, so only use profiles for those applications you actually run. Use the following list to determine the most likely candidates:

Network Agents
Web Applications
Cron Jobs

To find out which processes are currently running with open network ports and might need a profile to confine them, run aa-unconfined as root.

Example 19.1: Output of aa-unconfined
19848 /usr/sbin/cupsd not confined
19887 /usr/sbin/sshd not confined
19947 /usr/lib/postfix/master not confined
29205 /usr/sbin/sshd confined by '/usr/sbin/sshd (enforce)'

Each of the processes in the above example labeled not confined might need a custom profile to confine it. Those labeled confined by are already protected by AppArmor.

Tip
Tip: For More Information

For more information about choosing the the right applications to profile, refer to Section 20.2, “Determining Programs to Immunize”.

19.4 Building and Modifying Profiles

AppArmor on SUSE Linux Enterprise Server ships with a pre-configured set of profiles for the most important applications. In addition, you can use AppArmor to create your own profiles for any application you want.

There are two ways of managing profiles. One is to use the graphical front-end provided by the YaST AppArmor modules and the other is to use the command line tools provided by the AppArmor suite itself. Both methods basically work the same way.

For each application, perform the following steps to create a profile:

  1. As root, let AppArmor create a rough outline of the application's profile by running aa-genprof programname

    or

    Outline the basic profile by running YaST › AppArmor › Add Profile Wizard and specifying the complete path to the application you want to profile.

    A basic profile is outlined and AppArmor is put into learning mode, which means that it logs any activity of the program you are executing, but does not yet restrict it.

  2. Run the full range of the application's actions to let AppArmor get a very specific picture of its activities.

  3. Let AppArmor analyze the log files generated in Step 2 by typing S in aa-genprof.

    or

    Analyze the logs by clicking Scan System Log for AppArmor Events in the Add Profile Wizard and following the instructions given in the wizard until the profile is completed.

    AppArmor scans the logs it recorded during the application's run and asks you to set the access rights for each event that was logged. Either set them for each file or use globbing.

  4. Depending on the complexity of your application, it might be necessary to repeat Step 2 and Step 3. Confine the application, exercise it under the confined conditions, and process any new log events. To properly confine the full range of an application's capabilities, you might be required to repeat this procedure often.

  5. Once all access permissions are set, your profile is set to enforce mode. The profile is applied and AppArmor restricts the application according to the profile just created.

    If you started aa-genprof on an application that had an existing profile that was in complain mode, this profile remains in learning mode upon exit of this learning cycle. For more information about changing the mode of a profile, refer to Section 24.6.3.2, “aa-complain—Entering Complain or Learning Mode” and Section 24.6.3.3, “aa-enforce—Entering Enforce Mode”.

Test your profile settings by performing every task you need with the application you just confined. Normally, the confined program runs smoothly and you do not notice AppArmor activities at all. However, if you notice certain misbehavior with your application, check the system logs and see if AppArmor is too tightly confining your application. Depending on the log mechanism used on your system, there are several places to look for AppArmor log entries:

/var/log/audit/audit.log
/var/log/messages
dmesg

To adjust the profile, analyze the log messages relating to this application again as described in Step 3. Determine the access rights or restrictions when prompted.

Tip
Tip: For More Information

For more information about profile building and modification, refer to Chapter 21, Profile Components and Syntax, Chapter 23, Building and Managing Profiles with YaST, and Chapter 24, Building Profiles from the Command Line.

19.5 Configuring AppArmor Event Notification and Reports

Set up event notification in AppArmor so you can review security events. Event Notification is an AppArmor feature that informs a specified e-mail recipient when systemic AppArmor activity occurs under the chosen severity level. This feature is currently available in the YaST interface.

To set up event notification in YaST, proceed as follows:

  1. Make sure that a mail server is running on your system to deliver the event notifications.

  2. Start YaST. Then select AppArmor › AppArmor Control Panel. In Security Event Notification, select Configure.

  3. For each record type (Terse, Summary, and Verbose), set a report frequency, enter the e-mail address that should receive the reports, and determine the severity of events to log. To include unknown events in the event reports, check Include Unknown Severity Events.

    Note
    Note: Selecting Events to Log

    Unless you are familiar with AppArmor's event categorization, choose to be notified about events for all security levels.

  4. Leave this dialog with OK › Done to apply your settings.

Using AppArmor reports, you can read important AppArmor security events reported in the log files without manually sifting through the cumbersome messages only useful to the aa-logprof tool. You can decrease the size of the report by filtering by date range or program name.

To configure the AppArmor reports, proceed as follows:

  1. Start YaST. Select AppArmor › AppArmor Reports.

  2. Select the type of report to examine or configure from Executive Security Summary, Applications Audit, and Security Incident Report.

  3. Edit the report generation frequency, e-mail address, export format, and location of the reports by selecting Edit and providing the requested data.

  4. To run a report of the selected type, click Run Now.

  5. Browse through the archived reports of a given type by selecting View Archive and specifying the report type.

    or

    Delete unneeded reports or add new ones.

Tip
Tip: For More Information

For more information about configuring event notification in AppArmor, refer to Section 27.2, “Configuring Security Event Notification”. Find more information about report configuration in Section 27.3, “Configuring Reports”.

19.6 Updating Your Profiles

Software and system configurations change over time. As a result, your profile setup for AppArmor might need some fine-tuning from time to time. AppArmor checks your system log for policy violations or other AppArmor events and lets you adjust your profile set accordingly. Any application behavior that is outside of any profile definition can also be addressed using the Update Profile Wizard.

To update your profile set, proceed as follows:

  1. Start YaST and choose AppArmor › Update Profile Wizard.

  2. Adjust access or execute rights to any resource or for any executable that has been logged when prompted.

  3. Leave YaST after you have answered all questions. Your changes are applied to the respective profiles.

Tip
Tip: For More Information

For more information about updating your profiles from the system logs, refer to Section 23.5, “Updating Profiles from Log Entries”.

Print this page