whatis apparmor
AppArmor
A path-based mandatory access control system that confines programs with per-application profiles, default on Ubuntu, Debian, and openSUSE.
What Is AppArmor in Linux?
AppArmor profiles list which files, capabilities, and network access a specific program may use. Anything not listed is denied (in enforce mode) or just logged (in complain mode).
It is generally considered easier to write profiles for than SELinux because rules reference paths directly. aa-status shows which profiles are loaded and enforced.
Example
sudo aa-status Learn more about AppArmor
- AppArmor Explained AppArmor is a mandatory access control system for Linux that confines programs to a limited set of resources using per-application profiles. This guide covers how AppArmor works, how to read and write profiles, and how to move from complain mode to enforce mode.
- Writing AppArmor Profiles Building a profile from scratch with aa-genprof, what complain mode is for, and why AppArmor confines paths while SELinux labels inodes.