Hi, intrigeri: > Ben Hutchings: >> On Mon, 2017-10-23 at 10:06 +0200, [email protected] wrote: >>> A. Make AppArmor the default LSM in the kernel >> [...] >>> B. Configure bootloaders to enable AppArmor by default >>> >>> On https://bugs.debian.org/702030 a nice & flexible solution was >>> designed; let's call it B.1. >> [...] >>> A short-term simpler option would be to drop a file in >>> /etc/default/grub.d/ [...] Let's call this option B.2. >> [...]
>>> My personal preference is A > B.1. Ben & others, what do you think? >> I agree. > OK. Thanks for the prompt reply! For the record this was done in src:linux 4.13.10-1 whose changelog entry reads: * security: Enable DEFAULT_SECURITY_APPARMOR Cheers, -- intrigeri

