apparmor gets killed during change_hat operation
This document (7010509) is provided subject to the disclaimer at the end of this document.
Environment
Situation
This worked fine, but broke after updating the system to SLES11SP2.
Excerpt from audit log:
type=AVC msg=audit(1339184509.487:79554): apparmor="KILLED" operation="change_hat"....
Resolution
after that, run:
pam-config -a --apparmor
This correctly configures pam to make use of apparmor.
Cause
On SP1 it's necessary to configure pam manually. See /usr/share/doc/packages/pam_apparmor/README for details.
However, this is errorprone and breaks the pam configuration if the pam_apparmor rpm package is deinstalled without removing the added lines from the pam config files.
Decision was made to configure pam_apparmor on SP2 automatically to be able to remove the configuration while deinstallation of the rpm package.
Additional Information
Disclaimer
This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.
- Document ID:7010509
- Creation Date: 24-Jul-2012
- Modified Date:04-Oct-2022
-
- SUSE Linux Enterprise Server
For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com