You’re right but using apparmor is better than nothing no ? Additional security won’t harm anyone
Oh you was talking about the script installation… hum yes i thought the script will be a good idea at first but it’s bad and too complicated to maintain etc… i’m actually planning to create a deb package instead. The deb package will be much more easier to qubes users to install. I’ve never build a debian package so i’m currently struggling with basic things but once it will be finished i will remove the installation script in favor of the debian package.
I like challenge
but you’re 100% right about that learning selinux and also apparmor is hard but hey it’s not impossible
I listened to you i changed every salt files to match the value you recommended
The only value i didn’t removed is lockdown=confidentiality but the other value has ben removed. I didn’t removed the lockdown because it will not do any harm but if necessary i can remove it if you want
If you have any other suggestion tell me
Also due to our previous discussion i’m planning to create a minimal script in /etc/ to randomize the machine-id at boot like Whonix does.
But like i explained earlier apps will still know you’re a Qubes users anyway


