AA confining bash
pinguin74 <[email protected]>
| Newsgroups | gmane.linux.suse.security |
|---|---|
| Message-ID | <[email protected]> |
With regard to the lates Bash Shock, I wonder does it make sense to confine Bash with AppArmor after all? I think to create a dedicated profile solely for Bash does not make sense, because in general you want to be able to access everything with Bash, right? If an app wants to access Bash I envoke /bin/bash with the ix parameter, this way Bash inherits the app´s profile. Is this the only best way to confine Bash? Or does a dedicated profile make sense? Thanks
signature.asc
(application/pgp-signature, 455 B)
-----BEGIN PGP SIGNATURE----- iQEcBAEBAwAGBQJULwpLAAoJEEbP47fJHDB6dsMH/3raohimTcldV2aDPqi4wiV1 WpgYRcGIRvarmEnBOr6OFmflr3xcnxvk05eVGyjGLnMAU3lKOQme71g6krgAeX4K sRixw/xdi8fzw4PSv/JYVdOlIJ/n2tEbmkbBG7fzBXH+4pNkmnfg7vtV+hqd0tgk FZFXyf3WepBOQyC8qxMpf7Iqyi0Y3L+JldB42Ed8/QG3Az13OQKstT6FNKAd5Uv6 3k9XJmfKQylI3LF0BELyOd8in1NXt7b1M2XSUxmPRIX3lEMfbnIR1q6cPXGBHEdZ IhMvN2VxZOJJtOfBDh1ArcHkw9+r/X1d4f1pRDVVjE6AqKGBlrj4ywfHCDk/eV4= =jgIc -----END PGP SIGNATURE-----