Enabling AppArmor kernel LSM in Debian 7

August 25, 2014

I’ve installed apparmor and updated the default boot options in /boot/grub/menu.lst with apparmor=1 and security=apparmor. When I reboot and run sudo aa-status I am told that the kernel was not booted with those options.

What do I need to do to get this working?

  • The way that DigitalOcean creates VMs makes it impossible to set custom boot parameters. You’ll need to build a custom kernel with this option hard-coded.

Due to the virtualization technology that we use, the kernel running on the droplet must match what is being run on the hypervisor level. Boot parameters must be passed on the hypervisor. If you open a support ticket, the team should be able to get you squared away.

