Hello,
I have installed Proxmox Backup Server on top of Debian. It run nicely.
But Chrony for NTP synchronization won't start because of AppArmor:
When I delete the Chrony profile in AppArmor it starts normally. But with the AppArmor profile I get a lot of errors.
I compare the AppArmor Chrony profile with another Proxmox server (where Chrony runs normal, and AppArmor also), it is exactly the same...
When I run aa-status I get:
So, what can I do? Is the AppArmor profile needed for Chrony? Is it safe to run Chrony without the Chrony profile in AppArmor?
Thanks in advance!
I have installed Proxmox Backup Server on top of Debian. It run nicely.
But Chrony for NTP synchronization won't start because of AppArmor:
The unit chrony.service has entered the 'failed' state with result 'exit-code'.
audit[36381]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/chronyd" pid=36381 comm="chronyd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none
kernel: [B]audit: type=1400 audit(1679848187.998:306): apparmor="DENIED" operation="create" profile="/usr/sbin/chronyd" pid=36381 comm="chronyd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none[/B]
When I delete the Chrony profile in AppArmor it starts normally. But with the AppArmor profile I get a lot of errors.
I compare the AppArmor Chrony profile with another Proxmox server (where Chrony runs normal, and AppArmor also), it is exactly the same...
When I run aa-status I get:
apparmor module is loaded.
8 profiles are loaded.
8 profiles are in enforce mode.
/usr/bin/man
/usr/sbin/chronyd
lsb_release
man_filter
man_groff
nvidia_modprobe
nvidia_modprobe//kmod
tcpdump
0 profiles are in complain mode.
0 processes have profiles defined.
0 processes are in enforce mode.
0 processes are in complain mode.
0 processes are unconfined but have a profile defined.
So, what can I do? Is the AppArmor profile needed for Chrony? Is it safe to run Chrony without the Chrony profile in AppArmor?
Thanks in advance!
Last edited: