|
|
|
|
|
by ruthmarx
644 days ago
|
|
> The link rules can get pretty granular and seem explicitly designed to prevent that scenario. It's still an inherent weakness. No getting around that really. > Assuming the AppArmor profile allows writing to and executing the same files. Which isn't particularly common. I don't really want to try and come up with examples just so you can show there might be some hacky way of accomplishing something similar to what SELinux can offer - it would be missing my point. Point is there's a lot more you can do under AppArmor than SELinux. AppArmor isn't as granular and you can't lock down a system to the same extent, period. Is it good enough, sure. Is it better than nothing? Absolutely. Is it comparable to an optimized SELinux config? Not remotely. > This is possible with AppArmor. See above. |
|