ubuntu:apparmor:place_an_apparmor_profile_into_complain_mode
Ubuntu - AppArmor - Place an AppArmor Profile into Complain Mode
AppArmor confinement is provided via profiles loaded into the kernel, typically on boot. AppArmor profiles can be in one of two modes: enforcement and complain. Profiles loaded in enforcement mode will result in enforcement of the policy defined in the profile as well as reporting policy violation attempts (either via syslog or auditd). Profiles in complain mode will not enforce policy but instead report policy violation attempts.
sudo aa-complain /path/to/bin
The /etc/apparmor.d directory is where the AppArmor profiles are located. It can be used to manipulate the mode of all profiles.
Enter the following to place all profiles into complain mode:
sudo aa-complain /etc/apparmor.d/*
ubuntu/apparmor/place_an_apparmor_profile_into_complain_mode.txt · Last modified: 2020/07/15 09:30 by 127.0.0.1