mirror of
https://gitlab.com/apparmor/apparmor.git
synced 2025-03-04 16:35:02 +01:00

logprof/genprof and related utilities in python. Because the branch that was worked on was not based on the apparmor tree, not all of the history can be maintained for files that are not newly created or entirely rewritten in the branch. (This merge also includes a subsequent commit to the branch I was merging from which includes my missed bzr add of utils/apparmor/translations.py)
65 lines
2.1 KiB
Text
65 lines
2.1 KiB
Text
# This publication is intellectual property of Novell Inc. and Canonical
|
|
# Ltd. Its contents can be duplicated, either in part or in whole, provided
|
|
# that a copyright label is visibly located on each copy.
|
|
#
|
|
# All information found in this book has been compiled with utmost
|
|
# attention to detail. However, this does not guarantee complete accuracy.
|
|
# Neither SUSE LINUX GmbH, Canonical Ltd, the authors, nor the translators
|
|
# shall be held liable for possible errors or the consequences thereof.
|
|
#
|
|
# Many of the software and hardware descriptions cited in this book
|
|
# are registered trademarks. All trade names are subject to copyright
|
|
# restrictions and may be registered trade marks. SUSE LINUX GmbH
|
|
# and Canonical Ltd. essentially adhere to the manufacturer's spelling.
|
|
#
|
|
# Names of products and trademarks appearing in this book (with or without
|
|
# specific notation) are likewise subject to trademark and trade protection
|
|
# laws and may thus fall under copyright restrictions.
|
|
#
|
|
|
|
|
|
=pod
|
|
|
|
=head1 NAME
|
|
|
|
aa-enforce - set an AppArmor security profile to I<enforce> mode from
|
|
being disabled or I<complain> mode.
|
|
|
|
=head1 SYNOPSIS
|
|
|
|
B<aa-enforce I<E<lt>executableE<gt>> [I<E<lt>executableE<gt>> ...] [I<-d /path/to/profiles>] [I<-r>]>
|
|
|
|
=head1 OPTIONS
|
|
|
|
B<-d --dir / path/to/profiles>
|
|
|
|
Specifies where to look for the AppArmor security profile set.
|
|
Defaults to /etc/apparmor.d.
|
|
|
|
B<-r --remove>
|
|
|
|
Removes the enforce mode for the profile.
|
|
|
|
=head1 DESCRIPTION
|
|
|
|
B<aa-enforce> is used to set one or more profiles to I<enforce> mode.
|
|
This command is only relevant in conjunction with the I<aa-complain> utility
|
|
which sets a profile to complain mode and the I<aa-disable> utility which
|
|
unloads and disables a profile.
|
|
The default mode for a security policy is enforce and the I<aa-complain>
|
|
utility must be run to change this behavior.
|
|
|
|
The I<--remove> option can be used to remove the enforce mode for the profile,
|
|
setting it to complain mode.
|
|
|
|
=head1 BUGS
|
|
|
|
If you find any bugs, please report them at
|
|
L<https://bugs.launchpad.net/apparmor/+filebug>.
|
|
|
|
=head1 SEE ALSO
|
|
|
|
apparmor(7), apparmor.d(5), aa-complain(1), aa-disable(1),
|
|
aa_change_hat(2), and L<http://wiki.apparmor.net>.
|
|
|
|
=cut
|