Page 1 of 1

apparmor warning : named network rules not enforced

Posted: Thu Mar 20, 2014 11:10 am
by pedagang
if restart apparmor, appear warning : named network rules not enforced at /etc/apparmor.d/usr.sbin.named line 51

What this means ?

whether there is a bug of debian ?

Re: apparmor warning : named network rules not enforced

Posted: Sat Apr 05, 2014 1:16 pm
by MyKEcz
It's not bug of Debian. I don't know why but VestaCP in bash script installs apparmor-utils. In default installation, Debian doesn't have AppArmor enabled (only Ubuntu has this feature). It's smillar like SELinux but easier.

So you have 2 options:

1) You'll learn how to work with AppArmor (profiles, etc...). If you want to enable AppArmor:
# nano /etc/default/grub
find line GRUB_CMDLINE_LINUX_DEFAULT and add after quet security=apparmor:
GRUB_CMDLINE_LINUX_DEFAULT="quiet security=apparmor"
run:
# update-grub
then install additional AppArmor profiles:
# aptitude install apparmor-profiles
Reboot.
Problem solved. But you must add/edit downloaded profiles located in /etc/apparmor.d/

2) Easiest way, just disable/remove AppArmor.
# service apparmor stop
# update-rc.d -f apparmor remove
If you want completly remove from HDD:
# aptitude remove apparmor apparmor-utils libapparmor-perl libapparmor1 apparmor-profiles
# aptitude purge apparmor apparmor-utils libapparmor-perl libapparmor1 apparmor-profiles
I'm using Aptitude because of friendlier package management of dependencies when you install/remove.

MyKE

Re: apparmor warning : named network rules not enforced

Posted: Thu Apr 17, 2014 6:13 am
by pedagang
thanks
no problem about Named complaint

in debian distro,
after install vestacp, just need enable grub

Code: Select all

$ sudo perl -pi -e 's,GRUB_CMDLINE_LINUX="(.*)"$,GRUB_CMDLINE_LINUX="$1 apparmor=1 security=apparmor",' /etc/default/grub
$ sudo update-grub
$ sudo reboot
sudo service apparmor restart

Re: apparmor warning : named network rules not enforced

Posted: Fri Apr 18, 2014 7:22 pm
by imperio
I think we will disable apparmor when installing Vesta