AppArmor profiles for winbind, nmbd and smbd

Registered by Vikram Dhillon

This is to discuss what is needed to build and test the AppArmor profiles needed to confine winbind services, including Winbindd the sharing/authentication daemon, smbd and nmbd the applications/daemons that allow file sharing via the SMB protocol.

Blueprint information

Status:
Complete
Approver:
None
Priority:
Undefined
Drafter:
Vikram Dhillon
Direction:
Needs approval
Assignee:
Vikram Dhillon
Definition:
Obsolete
Series goal:
None
Implementation:
Unknown
Milestone target:
None
Completed by
Vikram Dhillon

Related branches

Sprints

Whiteboard

* See what services relate to winbindd
* Look for what files windbindd accesses
* Confine it to only those file and write the profile
* What other services using winbindd (like smbd and nmbd)
* How does that affect the files accessed by winbindd
* Can smbd and nmbd share a common profile
* Can we make a single profile that restricts what the file sharing daemons access

(?)

Work Items

This blueprint contains Public information 
Everyone can see this information.

Subscribers

No subscribers.