LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-28-2009, 05:42 PM   #1
DaveInRoseville
LQ Newbie
 
Registered: Jul 2009
Posts: 1

Rep: Reputation: 0
Feedback on AppArmor


Hi,

I'm interested in getting feedback from anyone who has deployed AppArmor in a corporate environment. Specifically I would like to know:

1. How much of a performance hit can I expect with AppArmor ?

2. Is it buggy ? How good is the support from SuSe for AppArmor ?

3. How user friendly is the policy parser ?

4. What are the basic gotcha's that I should be aware of when setting it up ?

5. How much disk space should I allocate for event logs ?

6. Is AppArmor better than SELinux ?

7. In your opinion, given the additional burden of managing and maintaining AppArmor, is it worth it ?

Any feedback would be appreciated. Thanks,

Dave
 
Old 07-30-2009, 11:00 PM   #2
cam34
Member
 
Registered: Aug 2003
Distribution: Fedora 22, Debian 8, Centos 6/7 for servers
Posts: 101

Rep: Reputation: 16
1. I'd expect minimal, as its kernel based File Access Controls, its sortof not really a process (Like Real Time Virus Scanning)

2. Buggy, not that I have come across, not sure about support although.

3. Easy, easy, easy. The conf files are simple, logprof is easy. The yast2 interface is probably just as easy.

4. Know what your app should be doing, Exercise it, exercise it and exercise it again. Review the profiles manaully helps too. Understand the syntax of conf files also.

5. Depends if you want to audit your applications, or just set and forget, I current have 66MB in apparmor log directory. 1 or 2GB for you /var maybe?

6. Different but so much more easier IMHO.

7. Yes. Easy as yell to setup and set and forget. Dont forget to setup application to complain and restart services when troubleshooting buggy applications, webservers playing up etc. A small headache there for a few days. lol.

Read to documentation on the OpenSuSe wiki its very good. SuSE CLE courseware has some good explanations on it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Is Apparmor Dying ? mihalisla Linux - Security 5 07-09-2009 08:51 PM
Problems with AppArmor nesrail Ubuntu 1 05-12-2009 08:29 AM
AppArmor Error house0fdust Linux - Security 2 08-16-2007 11:47 AM
AppArmor question Jordan&&&& Linux - Newbie 1 07-24-2007 06:35 AM
AppArmor: a little warning Robhogg Linux - Security 1 07-06-2006 11:22 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration