LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Mandriva
User Name
Password
Mandriva This Forum is for the discussion of Mandriva (Mandrake) Linux.

Notices


Reply
  Search this Thread
Old 08-23-2006, 02:22 AM   #1
Emmanuel_uk
Senior Member
 
Registered: Nov 2004
Distribution: Mandriva mostly, vector 5.1, tried many.Suse gone from HD because bad Novell/Zinblows agreement
Posts: 1,606

Rep: Reputation: 53
Port of apparmor to mandriva. Any instruction or howto or idea whether it is worth it


Talking about apparmor http://en.opensuse.org/Apparmor

Has anybody seen a good step by step instruction on how to install /port this into mandriva 2005 or 2006.
(I cannot find such details anymore, but I am sure it involves some kernel upgrade and rc.d scripts).
(or can anybody explain how they installed it. If I try to install it I will post here, but do not know when)

Has anybody got views about whether it is worth installing for a layered-paranoid approach to security for a desktop, with the caveat that I do not want to go down the complexity of SELinux. So it is not about competing against SELinux.

Some references:

"AppArmor Much Ado About Nothing" http://www.osreviews.net/reviews/security/apparmor

http://www.linux-magazine.com/issue/...vs_SELinux.pdf

About port to mandriva
RSBAC and AppArmor - linsec.ca Blog
http://linsec.ca/blog/index.php?/arc...-AppArmor.html
 
Old 08-23-2006, 09:10 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Let's make it clear I'm not favouring any solution over the other since it depends on what you want to do, but if you for instance look at GRSecurity vs SELinux apart from noticing they're incompatible (can't patch kernel with both):
- GRS provides security-enhancing features out of the box (even without using it's RBAC) but doesn't provide UI tools to work with (but since most of those knobs are sysctl-controlled that's no problem), the only distro I know supports it is Gentoo (cool choice folks) and it's not for those seeking EAL-like assurance.
- SELinux has different modes making choice between all-out or securing specific applications easier, it's (the only) part of the official kernel LSM framework, policy problems can be hard to fix but there's some new tools available that (should) make policy making easier.


Has anybody got views about whether it is worth installing for a layered-paranoid approach to security for a desktop, with the caveat that I do not want to go down the complexity of SELinux.
(Maybe a thread split between here and the Linux Security forum could have helped people notice it.) I think what you should do is get a wider view of the products available (LIDS, RSBAC, GRSecurity, SELinux and AppArmor), make a checklists of the key security enhancing features of each of the products and order on 0) how much of the features you need are covered by the product, 1) effort needed, 2) learning curve steepness and 3) ease of maintenance.

The outcome you then know of in what ways it enhances your boxens security (effectivity, assurance, holes to cover with other tools), at what price (cost as in knowledge, loss of current usability, time from build to production ready) and if it's a durable one (developer and community support, maintainability).


Increase-your-Mana-tenfold notice: finding out yourself by reading about those products and posting an objective comparison on LQ should earn you eternal gratitude of the whole community, I am pretty sure.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Which linux instruction is equivalent to windows' instruction "tracert"? backpacker Linux - Software 1 04-04-2006 10:55 PM
Mandriva 2006 pppoe setup HOWTO . Alessandro Mandriva 1 10-19-2005 09:45 PM
Mandriva 2005 LE - Is it worth it? RySk8er30 Mandriva 45 09-30-2005 08:31 PM
Mandriva LE 2005 Worth it? Slapdash Mandriva 8 05-14-2005 09:03 PM
Is this a good idea for updating to Mandriva 2005? Zmaster115 Mandriva 1 05-02-2005 02:30 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Mandriva

All times are GMT -5. The time now is 10:27 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration