AA confining bash

pinguin74 <[email protected]>
Newsgroups gmane.linux.suse.security
Message-ID <[email protected]>
With regard to the lates Bash Shock, I wonder does it make sense to
confine Bash with AppArmor after all?

I think to create a dedicated profile solely for Bash does not make
sense, because in general you want to be able to access everything with
Bash, right?

If an app wants to access Bash I envoke /bin/bash with the ix parameter,
this way Bash inherits the app´s profile. Is this the only best way to
confine Bash? Or does a dedicated profile make sense?

Thanks
signature.asc (application/pgp-signature, 455 B)
-----BEGIN PGP SIGNATURE-----

iQEcBAEBAwAGBQJULwpLAAoJEEbP47fJHDB6dsMH/3raohimTcldV2aDPqi4wiV1
WpgYRcGIRvarmEnBOr6OFmflr3xcnxvk05eVGyjGLnMAU3lKOQme71g6krgAeX4K
sRixw/xdi8fzw4PSv/JYVdOlIJ/n2tEbmkbBG7fzBXH+4pNkmnfg7vtV+hqd0tgk
FZFXyf3WepBOQyC8qxMpf7Iqyi0Y3L+JldB42Ed8/QG3Az13OQKstT6FNKAd5Uv6
3k9XJmfKQylI3LF0BELyOd8in1NXt7b1M2XSUxmPRIX3lEMfbnIR1q6cPXGBHEdZ
IhMvN2VxZOJJtOfBDh1ArcHkw9+r/X1d4f1pRDVVjE6AqKGBlrj4ywfHCDk/eV4=
=jgIc
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.