Information
Configure AppArmor to be enabled at boot time and verify that it has not been overwritten
by the bootloader boot parameters.
Rationale:
AppArmor must be enabled at boot time in your bootloader configuration to ensure that
the controls it provides are not overridden.
Solution
For grub based systems edit /boot/grub/menu.lst and remove all instances of apparmor=0
on all kernel lines.
For grub2 based systems edit /etc/default/grub and remove all instances of apparmor=0
from all CMDLINE_LINUX parameters:
GRUB_CMDLINE_LINUX_DEFAULT="quiet"
GRUB_CMDLINE_LINUX=""
Run the following command to update the grub2 configuration:
# update-grub
Notes:
This recommendation is designed around the grub bootloader, if LILO or another
bootloader is in use in your environment enact equivalent settings.
Replace /boot/grub/menu.lst with the appropriate grub configuration file for your
environment.