Is it a bad idea to run SELinux and AppArmor at the same time?
Posted
by
jgbelacqua
on Ask Ubuntu
See other posts from Ask Ubuntu
or by jgbelacqua
Published on 2011-01-26T20:00:02Z
Indexed on
2011/01/29
7:33 UTC
Read the original article
Hit count: 325
My corporate policy says that Linux boxes must be secured with SELinux (so that a security auditor can check the 'yes, we're extremely secure!' checkbox for each server). I had hoped to take advantage of Ubuntu's awesome default AppArmor security. Is it unwise to run both Apparmor and SELinux? (If so, can this bad idea be mitigated with some apparmor and/or selinux tweaks?)
Update 1/28 -- Kees Cook has pointed out in his answer the dead simple reason why it's a bad idea to run both -- the Linux kernel says you can't1. [ 1 More precisely, the Linux Security Modules interface framework is designed for a single running implementation, and does not support more than a single running implementation. ]
Update 1/27 -- I've accepted the answer from kenny.r , though I would be happier with some more technical reasons of why this would fail, or examples of actual conflicts that this would cause.
© Ask Ubuntu or respective owner