Re: [apparmor] RFC: Patch [Bug 1207424] Re: mod_apparmor should let me use ServerName as default hat name

2013-08-06 Thread Kees Cook
On Fri, Aug 02, 2013 at 01:41:37AM -0700, John Johansen wrote: > This is a first pass at providing the feature requested in Bug 1207424 > > It leverages the appache config option > > AADefaultHatName > > and when its value is specified as > > > the hostname will be looked up and used. Obv

Re: [apparmor] [RFC] handling XDG user directories

2013-08-06 Thread John Johansen
On 08/06/2013 12:18 PM, Jamie Strandboge wrote: > On 08/06/2013 01:45 PM, John Johansen wrote: >> On 08/05/2013 03:59 PM, Jamie Strandboge wrote: > >>> and users/admins can adjust /etc/apparmor.d/tunables/xdg-dirs or drop files >>> into >>> /etc/apparmor.d/tunables/xdg-dirs.d, providing a welcome

Re: [apparmor] [RFC] handling XDG user directories

2013-08-06 Thread Jamie Strandboge
On 08/06/2013 01:45 PM, John Johansen wrote: > On 08/05/2013 03:59 PM, Jamie Strandboge wrote: >> and users/admins can adjust /etc/apparmor.d/tunables/xdg-dirs or drop files >> into >> /etc/apparmor.d/tunables/xdg-dirs.d, providing a welcome convenience[2]. >> ... > I know that people like the dr

Re: [apparmor] [RFC] handling XDG user directories

2013-08-06 Thread John Johansen
On 08/05/2013 03:59 PM, Jamie Strandboge wrote: > = Background = > > The xdg-user-dirs specification[1] allows for translatable and movable common > directories. While this may be beneficial for users who for example want to > have > ~/Pictures translated into their own language, this flexibility

[apparmor] handling XDG user directories

2013-08-06 Thread Daniel Curtis
Hi, It is a very good idea, really! For now, if I remember correctly, installing *ubuntu 12.04 and trying to enforce a default Firefox profile, which contains: owner @{HOME}/ r, owner @{HOME}/Public/ r, owner @{HOME}/Public/* r, owner @{HOME}/Download/ r, owner @{HOME}/Download/* rw, there is a

[apparmor] lightdm profile from a apparmor.d/abstractions directory.

2013-08-06 Thread Daniel Curtis
Hi Mr Seth, Thank you, for providing me an information, about a guest account protections. Generally, I mean a confirmation, that this account is well protected. Anyway, I was just freaking out about a default 'lightdm-guest-session' profile and that - for me - it seems empty. So I was thinking, t