Loading…
May 21 - 22 | Minneapolis, Minnesota
View More Details & Registration
Note: The schedule is subject to change.

The Sched app lets you build your schedule, but it is not a substitute for event registration. You must be registered for Linux Security Summit North America 2026 to participate in the sessions. If you have not registered but would like to join us, please visit the event registration page to purchase a ticket.


Friday May 22, 2026 9:55am - 10:40am CDT
AppArmor has traditionally used a more static type enforcement style policy, where all object accesses must be explicitly allowed within the a subjects profile. However this can result in policy that has overly broad access rights to cover all the potential accesses the application may do.

Object capabilities allow passing objects to a subject such that the object carries the opening tasks access rights. This allows extending a subject access permissions dynamically. Allowing for smaller more dynamic policy, but while loosing some of the advantages of the more static type enforcement policy.

This presentation will discuss how AppArmor is bringing bounded object delegation to its policy, and the the affects it has on how this can change how policy is authored.
Speakers
avatar for John Johansen

John Johansen

Security Engineer, Canonical
John Johansen began working with open source software in the late 80s and began playing with Linux in 93. He completed a masters in mathematics at the University of Waterloo and the began working for Immunix doing compiler hardening, and then AppArmor. After Immunix was acquired by... Read More →
Friday May 22, 2026 9:55am - 10:40am CDT
101A+B

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link