Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #227852 > unrolled thread
| Started by | Jesper Dybdal <jd-debian-user@dybdal.dk> |
|---|---|
| First post | 2020-10-16 12:30 +0200 |
| Last post | 2020-10-16 20:20 +0200 |
| Articles | 7 — 4 participants |
Back to article view | Back to linux.debian.user
Stretch => Buster: AppArmor Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-10-16 12:30 +0200
Re: Stretch => Buster: AppArmor Reco <recoverym4n@enotuniq.net> - 2020-10-16 12:40 +0200
Re: Stretch => Buster: AppArmor Tixy <tixy@yxit.co.uk> - 2020-10-16 16:40 +0200
Re: Stretch => Buster: AppArmor Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-10-16 17:00 +0200
Re: Stretch => Buster: AppArmor Tixy <tixy@yxit.co.uk> - 2020-10-16 17:20 +0200
Re: Stretch => Buster: AppArmor Reco <recoverym4n@enotuniq.net> - 2020-10-16 17:00 +0200
Re: Stretch => Buster: AppArmor l0f4r0@tuta.io - 2020-10-16 20:20 +0200
| From | Jesper Dybdal <jd-debian-user@dybdal.dk> |
|---|---|
| Date | 2020-10-16 12:30 +0200 |
| Subject | Stretch => Buster: AppArmor |
| Message-ID | <B0v9L-4bV-5@gated-at.bofh.it> |
At some point I will have to upgrade from Stretch to Buster, and I am beginning to consider which problems I might run into. So I have some more or less stupid questions that I will post in separate threads - this is the first. Buster enables AppArmor by default. I know just about nothing at all about AppArmor. Does it constitute a risk that some of my existing programs will not work? For instance, my postfix installation (which is by far the most important application I run) uses a few non-standard tcp ports to comunicate with helper services and to receive mail submissions - is there a risk that AppArmor will block that? Is there a simple way to disable AppArmor completely until I've had time to figure out what to do with it long-term? Thanks, Jesper -- Jesper Dybdal https://www.dybdal.dk
[toc] | [next] | [standalone]
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Date | 2020-10-16 12:40 +0200 |
| Message-ID | <B0vjr-4f4-9@gated-at.bofh.it> |
| In reply to | #227852 |
Hi. On Fri, Oct 16, 2020 at 12:23:30PM +0200, Jesper Dybdal wrote: > Buster enables AppArmor by default. I know just about nothing at all > about AppArmor. Does it constitute a risk that some of my existing > programs will not work? Depends. AppArmor is applied per-binary. If you're using something that ships an AppArmor policy - it will be enabled. > For instance, my postfix installation (which is by far the most > important application I run) uses a few non-standard tcp ports to > comunicate with helper services and to receive mail submissions - is > there a risk that AppArmor will block that? No, because there's no shipped AppArmor policy for postfix in buster. > Is there a simple way to disable AppArmor completely until I've had > time to figure out what to do with it long-term? Adding "apparmor=0" to your kernel cmdline should do the trick. Reco
[toc] | [prev] | [next] | [standalone]
| From | Tixy <tixy@yxit.co.uk> |
|---|---|
| Date | 2020-10-16 16:40 +0200 |
| Message-ID | <B0z3I-6sr-3@gated-at.bofh.it> |
| In reply to | #227855 |
On Fri, 2020-10-16 at 13:30 +0300, Reco wrote: > > On Fri, Oct 16, 2020 at 12:23:30PM +0200, Jesper Dybdal wrote: [...] > > Is there a simple way to disable AppArmor completely until I've had > > time to figure out what to do with it long-term? > > Adding "apparmor=0" to your kernel cmdline should do the trick. Or do what I did, just uninstall the apparmor package which is pulled in as a 'recommends' of the Linux kernel. Or pin it to priority -1 for extra paranoia. -- Tixy
[toc] | [prev] | [next] | [standalone]
| From | Jesper Dybdal <jd-debian-user@dybdal.dk> |
|---|---|
| Date | 2020-10-16 17:00 +0200 |
| Message-ID | <B0zn3-6zN-1@gated-at.bofh.it> |
| In reply to | #227869 |
On 2020-10-16 16:39, Tixy wrote: > Or do what I did, just uninstall the apparmor package which is pulled > in as a 'recommends' of the Linux kernel. Or pin it to priority -1 for > extra paranoia. > Thanks. But will it not be reinstalled the next time there is a kernel update? -- Jesper Dybdal https://www.dybdal.dk
[toc] | [prev] | [next] | [standalone]
| From | Tixy <tixy@yxit.co.uk> |
|---|---|
| Date | 2020-10-16 17:20 +0200 |
| Message-ID | <B0zGq-6VN-15@gated-at.bofh.it> |
| In reply to | #227871 |
On Fri, 2020-10-16 at 16:59 +0200, Jesper Dybdal wrote: > On 2020-10-16 16:39, Tixy wrote: > > Or do what I did, just uninstall the apparmor package which is > > pulled > > in as a 'recommends' of the Linux kernel. Or pin it to priority -1 > > for > > extra paranoia. > > > > Thanks. But will it not be reinstalled the next time there is a kernel > update? Good question, I have apt configured not to install recommends. Makes me wonder how apparmour got installed in the first place. Maybe it was there from previous debian versions and the update just enabled it. (I uninstalled it because after the upgrade to Buster I got loads of apparmour warnings at boot.) -- Tixy
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Date | 2020-10-16 17:00 +0200 |
| Message-ID | <B0zn5-6zN-23@gated-at.bofh.it> |
| In reply to | #227869 |
Hi. On Fri, Oct 16, 2020 at 03:39:29PM +0100, Tixy wrote: > On Fri, 2020-10-16 at 13:30 +0300, Reco wrote: > > > > On Fri, Oct 16, 2020 at 12:23:30PM +0200, Jesper Dybdal wrote: > [...] > > > Is there a simple way to disable AppArmor completely until I've had > > > time to figure out what to do with it long-term? > > > > Adding "apparmor=0" to your kernel cmdline should do the trick. > > Or do what I did, just uninstall the apparmor package which is pulled > in as a 'recommends' of the Linux kernel. Or pin it to priority -1 for > extra paranoia. That will work too. In buster, apparmor is just another system service that's started during the boot process. Removing it will remove all both the security and possible breakage that AppArmor provides. Reco
[toc] | [prev] | [next] | [standalone]
| From | l0f4r0@tuta.io |
|---|---|
| Date | 2020-10-16 20:20 +0200 |
| Message-ID | <B0CuB-bw-5@gated-at.bofh.it> |
| In reply to | #227852 |
Hi, 16 oct. 2020 à 12:23 de jd-debian-user@dybdal.dk: > Is there a simple way to disable AppArmor completely until I've had time to figure out what to do with it long-term? > Considering you are not asking for removal but just deactivation, the simplest way to me seems to be the following: sudo systemctl stop apparmor (=> stop the service now) sudo systemctl disable apparmor (=> prevent the service to be started at next reboot) Best regards, l0f4r0
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web