Hope everything is having a great weekend. With that big update that came through the other day I felt it was a good time to do my routine fresh install just to keep things clean. When I applied the “hardened-debian” apparmor profiles I am getting these profiles in complain mode on the workstation:
I did originally use the new command of “sudo apt-get install apparmor-profiles apparmor-profiles-extra apparmor-profiles-hardened-debian”. I tried it again this afternoon, just to make sure. I did a new install of 15.0.0.3.3 followed by that new large update. I then did the “hardened-debian” command with the same result of those 16 profiles in complain mode.
These profiles are not mature enough to be shipped in enforce mode by default on Debian. They are shipped in complain mode so that users can test them, choose which are desired, and help improve them upstream if needed.