LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Linux Mint
User Name
Password
Linux Mint This forum is for the discussion of Linux Mint.

Notices


Reply
  Search this Thread
Old 07-17-2020, 10:52 AM   #1
crujones4
Member
 
Registered: Jun 2020
Location: Atlantis
Distribution: Mint
Posts: 66

Rep: Reputation: Disabled
Installing Apparmor or Firejail on Mint?


I've recently come across numerous videos suggesting the importance of additional hardening w.Firejail or Apparmor.

One, the other or both?

https://www.invidio.us/watch?v=MVLrclfbS4U
https://www.invidio.us/watch?v=JFjXvIwAeVI
https://firejail.wordpress.com/

^ These are the resources I currently have, but am a relative newb, and definitely want to set it up.

Question:
Can someone provide a step-by-step line guide to installing FJ? Do I want to Firetools with it? I heard on Aaron Jone's video [12:40 in] that "firecnfg" will firejail every single app on your system, but it sometimes has unintended consequences.

What I'm looking for here:
A simple way of hardening my system by separating the app access, with a list explaining how to do it.


-Seriously appreciate all the help here, am grateful for such a concerned community, and hopeful to be in the same position one day so that I can help people make the Linux switch. Thanks so much again
 
Old 07-17-2020, 03:05 PM   #2
shruggy
Senior Member
 
Registered: Mar 2020
Posts: 3,670

Rep: Reputation: Disabled
Firejail may be easier to use because it comes equipped out of the box with profiles for many applications (on Debian-based systems, they're in package firejail-profiles). So, if all your uses are covered by them then you don't need to configure anything.

OTOH, if you use applications not listed there and don't know (or don't want to learn) how to write Firejail profiles for them, then AppArmor offers a more generic solution including a learning mode.

Mind you, AppArmor also comes with some ready-made profiles (in package apparmor-profiles), but most of them seem rather to be geared toward server uses.
 
1 members found this post helpful.
Old 07-20-2020, 01:16 PM   #3
crujones4
Member
 
Registered: Jun 2020
Location: Atlantis
Distribution: Mint
Posts: 66

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by shruggy View Post
Firejail may be easier to use because it comes equipped out of the box with profiles for many applications (on Debian-based systems, they're in package firejail-profiles). So, if all your uses are covered by them then you don't need to configure anything.

OTOH, if you use applications not listed there and don't know (or don't want to learn) how to write Firejail profiles for them, then AppArmor offers a more generic solution including a learning mode.

Mind you, AppArmor also comes with some ready-made profiles (in package apparmor-profiles), but most of them seem rather to be geared toward server uses.
Excellent advise--I really appreciate it.

Unfortunately, I'm still unsure how to install Firejail. :/

When I type the command[s] into the line,
it runs processes, but firejail is nowhere to be found in my applications.

Any help?

-Thanks so much again
 
Old 07-21-2020, 01:37 PM   #4
crujones4
Member
 
Registered: Jun 2020
Location: Atlantis
Distribution: Mint
Posts: 66

Original Poster
Rep: Reputation: Disabled
? ? ? ?
 
Old 07-21-2020, 04:40 PM   #5
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by crujones4 View Post
? ? ? ?
???
 
Old 07-22-2020, 01:02 PM   #6
crujones4
Member
 
Registered: Jun 2020
Location: Atlantis
Distribution: Mint
Posts: 66

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by ondoho View Post
???
"Unfortunately, I'm still unsure how to install Firejail. :/

When I type the command[s] into the line,
it runs processes, but firejail is nowhere to be found in my applications."

I found the command lines online, and when I put them in, it listed a number of processes as being activated,
but afterwards, firejail was nowhere to be found.

Any chance you could let me know the right command lines in order to install it properly?

-Sincerely appreciate all the help here
 
Old 07-23-2020, 01:47 AM   #7
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by crujones4 View Post
"Unfortunately, I'm still unsure how to install Firejail. :/

When I type the command[s] into the line,
it runs processes, but firejail is nowhere to be found in my applications."

I found the command lines online, and when I put them in, it listed a number of processes as being activated,
but afterwards, firejail was nowhere to be found.

Any chance you could let me know the right command lines in order to install it properly?

-Sincerely appreciate all the help here
It is installed.
firejail is a command line application, it won't show up in your GUI menu.
If you're not comfortable using the command line you won't be comfortable using firejail either. Sorry.
 
Old 08-28-2020, 06:25 AM   #8
lisamint
Member
 
Registered: Nov 2019
Posts: 36

Rep: Reputation: Disabled
Creating Firejail profiles using the GUI?

Hi everyone,

Does anybody know how to add (customised) profiles on Firejail using the user interface rather than on the terminal? I have been searching online but I have not found anything at all. For example, I tried to add CherryTree using the path below (executable file?) but did not work; actually, it does not even display the cherrytree icon on the GUI once the steps on the configuration wizard are completed:

/var/lib/flatpak/app/com.giuspen.cherrytree/current/b4c816bbcf50260aacaf9e258096d3619eaf15c6707da0b3986c9158074721c8/export/bin

Is there any way to do it? Any guidelines or suggestions, please?

Thanks.
 
Old 08-28-2020, 10:37 AM   #9
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
^ I'm not firejail will even work with flatpaks.
https://github.com/flatpak/flatpak/issues/66
 
  


Reply

Tags
apparmor, firejail, hardening



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Simple Application Sandboxing Using AppArmor and Firejail LXer Syndicated Linux News 0 06-18-2020 05:01 AM
LXer: Parrot Security 3.10 Ethical Hacking OS Adds Full Firejail/AppArmor Sandboxing LXer Syndicated Linux News 0 12-16-2017 09:12 PM
[SOLVED] Does Mint 18 ship with Apparmor and SELinux? Novatian Linux - Security 6 09-17-2016 07:01 AM
How to install apparmor in Mint? Novatian Linux - Security 1 02-26-2015 04:19 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Linux Mint

All times are GMT -5. The time now is 09:31 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration