On Sun, 20 Aug 2017 16:42:55 +0200 Laurent Bigonville <bigon@debian.org> wrote:
IMVHO, in regard to the recent proposal of enabling apparmor in debian by default, this needs to be addressed first.
Yes this is very important, although we have aa-logprof to be used as auditing tool, but I agree that not seeing AppArmor events in your custom auditd report is rather bad. We could ask John Johansen if he has it on it's queue. He is upstreaming Ubuntu patches to mainline Linux, so I guess we depend on his work entirely.