[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Let's enable AppArmor by default (why not?)



On 10/31/2017 09:52 PM, gregor herrmann wrote:
> On Tue, 31 Oct 2017 19:51:34 +0100, Philipp Kern wrote:
>> I'm not sure if I missed some kind of alert tool like the selinux
>> troubleshooting bits, but in my case it just silently failed: 
> In case you don't know it, apparmor-notify has been helpful for me.

Thanks for the pointer! I indeed didn't know about it yet.

With the omni.js denial it's a tad noisy and the user has to be in group
adm to read /var/log/kern.log (because dmesg is restricted to root these
days). But at least it's immediate when a denial happens, so that's good. :)

Kind regards
Philipp Kern

Attachment: signature.asc
Description: OpenPGP digital signature


Reply to: