> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure AppArmor for charon

> Allow charon to read the Futurex module, endpoint configuration, TLS files, and operation logs.

Ubuntu confines charon with AppArmor. Add the installed Futurex paths before you restart strongSwan.

## Add the local policy

```shell theme={null}
sudo install -d -m 755 /etc/apparmor.d/local

sudo tee /etc/apparmor.d/local/usr.lib.ipsec.charon \
  > /dev/null <<'EOF'
/usr/local/lib/libcryptohub-pkcs11.so mr,
/etc/strongswan-chlibs/ r,
/etc/strongswan-chlibs/** r,
/var/log/charon-debug.log rw,
/tmp/chlibs-auth.pem rw,
/tmp/chlibs-auth.pem.sha256 rw,
EOF
```

The temporary PEM rules allow FxChlibs to prepare its client-authentication material during module initialization.

## Reload and verify the policy

```shell theme={null}
sudo apparmor_parser -r /etc/apparmor.d/usr.lib.ipsec.charon
sudo systemctl restart strongswan-starter
sudo journalctl -k --since "2 minutes ago" --no-pager \
  | grep -i 'apparmor.*DENIED' \
  | grep -E 'charon|cryptohub|chlibs-auth' || true
```

<Check>
  The final command must not return a denial for a Futurex module, configuration, TLS, log, or temporary authentication path.
</Check>

<Note>
  If you install the endpoint unit in different directories, add those exact paths to the local override. Do not copy the example paths without matching your installation.
</Note>
