* RE: SELinux Dumb Questions
@ 2002-06-04 23:37 Roland.Jones
2002-06-05 4:26 ` Ed Street
2002-06-05 5:34 ` Outside Observer Comments Paul Wolfson
0 siblings, 2 replies; 8+ messages in thread
From: Roland.Jones @ 2002-06-04 23:37 UTC (permalink / raw)
To: russell, jw, selinux
Cc: tom_haigh, admissions, carsten.grohmann, linux-security-module
Russell,
Your comments and clarifications are most enlightening and reflect my under standing of SELinux's use as open source code. I find this issue of private licensing confusing since I thought the whole idea was to get this technology into the community. The NSA's SELinux overview says the following at the end of the page:
Security-enhanced Linux is being released under the same terms and conditions as the original sources. The release includes documentation and source code for both the system and some system utilities that were modified to make use of the new features. Participation with comments, constructive criticism, and/or improvements is welcome.
It doesn't seem to me that NSA's intention was to restrict the deployment of this technology when they released SELinux. Any NSA types out there?
Roland
-----Original Message-----
From: ext Russell Coker [mailto:russell@coker.com.au]
Sent: Tuesday, June 04, 2002 3:00 PM
To: jw@centraltexasit.com; selinux@tycho.nsa.gov
Cc: Haigh, Tom; 'Admissions Office'; Carsten Grohmann;
linux-security-module@wirex.com
Subject: Re: SELinux Dumb Questions
On Tue, 4 Jun 2002 23:30, JW wrote:
> > On Mon, 3 Jun 2002 16:50, Admissions Office wrote:
> > > Folks this may seem like a dumb question given the Open Source and
> > > postings on the site. Its just that we want to be sure....
> > >
> > > Is there any reason why a Colo company cannot offer SELinux as a
> > > standard product offering they would install on clients servers?
> >
> > As Mark stated there are no license or legal issues preventing such use.
>
> On Monday 03 June 2002 04:13 pm, Haigh, Tom wrote:
> > SELinux includes Type Enforcement technology developed and patented by
> > the Secure Computing Corporation, who still holds rights to all
> > commercial use of the technology. Before a colo company, or anyone else
> > uses the technology commercially, it will be necessary to negotiate a
> > license with Secure Computing. If anyone wants to do so, I can help get
> > the ball rolling with our Legal and BD folks.
Let's look at the following URL:
http://www.securecomputing.com/archive/press/2000/nsa_faq_secure_linux.html
> Question 6: Will SCC use its patent on Type Enforcement TM to restrict use,
> future development, derivative work, or release of the source code of the
> system?
>
> There will be no restrictions on the use of TE by the Linux open source
> community. We believe that leveraging the resources of the Linux community
> is the best way to develop robust security for Linux.
That seems like a clear statement that we can do what we like with it!
But Tom, if your company does want to go ahead with this patent plan then
please do the following:
1) Change that misleading web page.
2) Let me know so I can remove all SE Linux code from Debian, remove it from
my client's machines, and start work on a competing product.
3) Make formal statements as to limitations of distribution etc, also
clarify to what extent you want SE Linux code removed from the world. Should
I get the upstream maintainer of stat to remove the SE Linux code too? Also
you'll have to get it removed from LSM which is under the GPL, and you had
better hope that the problems with building as a module are fixed quickly -
you can't ship code that links with the kernel unless it's under the GPL.
PS When does the patent expire? If it's due to expire in 1 year or less we
can just wait until it's gone...
--
I do not get viruses because I do not use MS software.
If you use Outlook then please do not put my email address in your
address-book so that WHEN you get a virus it won't use my address in the
>From field.
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 8+ messages in thread
* RE: SELinux Dumb Questions
2002-06-04 23:37 SELinux Dumb Questions Roland.Jones
@ 2002-06-05 4:26 ` Ed Street
2002-06-05 5:34 ` Outside Observer Comments Paul Wolfson
1 sibling, 0 replies; 8+ messages in thread
From: Ed Street @ 2002-06-05 4:26 UTC (permalink / raw)
To: selinux
Hello,
Hey I'm all for any open structure that could meet c2 or better security
guidelines. I believe that selinux comes closer than anything else on
the market. I also believe that if the NSA or any other group wishes to
mangle/modify/add/remove/etc code from other vendors to meet those
guidelines then it's their right (baring copyright infringment and close
source) I also think a lot of people can benefit greatly from this
project and I would really hate to see some greedy company attempt to
snuff the project into their folds.
However after reviewing all the previous emails I have put all my
selinux projects on hold untill I find out where this is going. Just
remember people, if security was illegal only criminals would have
security.
Ed
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: Outside Observer Comments
2002-06-04 23:37 SELinux Dumb Questions Roland.Jones
2002-06-05 4:26 ` Ed Street
@ 2002-06-05 5:34 ` Paul Wolfson
1 sibling, 0 replies; 8+ messages in thread
From: Paul Wolfson @ 2002-06-05 5:34 UTC (permalink / raw)
To: Roland.Jones, russell, jw, selinux
Cc: tom_haigh, admissions, carsten.grohmann, linux-security-module
To SELinux WG:
I am sorry for my jumping to conclusions based on a very short baseline of
email. I hope that no offense has been taken. I will stay on the sidelines
of what is obviously a very well thought out process.
Paul Wolfson
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 8+ messages in thread
* RE: Sorry, read this one: Re: SELinux Dumb Questions
@ 2002-06-04 22:28 McFadden, Ken
2002-06-05 2:43 ` Outside observer comments Paul Wolfson
0 siblings, 1 reply; 8+ messages in thread
From: McFadden, Ken @ 2002-06-04 22:28 UTC (permalink / raw)
To: 'Russell Coker', JW, SE Linux
Cc: Haigh, Tom, 'Admissions Office', Carsten Grohmann
Once again, We are doing this for NSA and GNU NOT SECURE COMPUTING!!!!!!!
If Tom has a problem then they need to address it with the NSA and the
NSA can go forth and remove their crap or deem it as being GNU.....As I
see it SELinux will go on and if someone would like to use it then all
they would need to do is keep the original GNU licensing with it.....
Other words this is not our problem to work out but Tom's and NSA's........
Until then I would treat it as GNU per NSA's web page!!!!!!!
-----Original Message-----
From: Russell Coker [mailto:russell@coker.com.au]
Sent: Tuesday, June 04, 2002 4:12 PM
To: JW; SE Linux
Cc: Haigh, Tom; 'Admissions Office'; Carsten Grohmann
Subject: Re: Sorry, read this one: Re: SELinux Dumb Questions
On Tue, 4 Jun 2002 23:49, JW wrote:
> Sorry about that last empty message, I accidently hit ^[ENTER] when I
meant
> hit shift...
You had written enough to clarify the issue (I don't know how I missed Tom's
message the first time).
> IANAL, but it is my understanding that you cannot restrict the use or
> distribution of GPLd Free Software. It simply does not work that way, no
> exceptions, no excuses. Once code is GPLd it is free for all to use. You
> can change the license on future versions of the code, but you cannot go
> back and restrict GPL's code "after the fact"
Yes. Unless of course they claim that they didn't GPL it, or that the GPL
only covers the code not the patent.
> 2. It will need to be removed from Debian's tree -- at least moved to
> non-free, yet as I said before, if Secure Computing is correct, SE-Linux
is
> not legal to use with GPL'd software anyway (at least the way I see it).
Stuff that. I'm not putting this much work into non-free stuff! If the
license gets changed to anything other than the GPL then I'll immediately
cease work and file critical bug reports against ftp.debian.org asking for
the packages to be removed. If Secure Computing want me to work on material
that's patented by them then they'll have to pay me at my usual consulting
rates, plus back-pay for the last 6 months.
> You'd better bet that GNU and other people who's code is being modified to
> work with SE-Linux will have ten purple cows on anyone who mixes non-free
> code with their GPLd code.
The code can be still released as patches, but the problems of having them
becoming obsolete and not matching the version your OS uses will remain.
Basically I think that SE Linux is as good as dead for anything other than
research use if this patent gets enforced.
--
I do not get viruses because I do not use MS software.
If you use Outlook then please do not put my email address in your
address-book so that WHEN you get a virus it won't use my address in the
>From field.
--
You have received this message because you are subscribed to the selinux
list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov
with
the words "unsubscribe selinux" without quotes as the message.
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 8+ messages in thread
* Outside observer comments
2002-06-04 22:28 Sorry, read this one: Re: SELinux Dumb Questions McFadden, Ken
@ 2002-06-05 2:43 ` Paul Wolfson
2002-06-05 3:14 ` Russell Coker
` (2 more replies)
0 siblings, 3 replies; 8+ messages in thread
From: Paul Wolfson @ 2002-06-05 2:43 UTC (permalink / raw)
To: McFadden, Ken, 'Russell Coker', JW, SE Linux
Cc: Haigh, Tom, 'Admissions Office', Carsten Grohmann,
Paul Wolfson
Hello,
I recently added myself to the SELinux listserver because of genuine shared
concerns about securing open source computing. NSA is correct to be doing
this initiative and linux in its evolution will be better for it.
Now, from the few dozen emails that have come across my screen are any
indication, bickering is counter-productive. It resembles government
procurement at its worst. In that atmosphere I am afraid that there is
little that I will be able to contribute. My company, is relatively new,
but has principal engineers who hold or have held DoD clearance at TS and
higher and would be interested in contributing to this effort. If someone
on this list is a good POC let me know and perhaps we will be in a position
to help.
Perhaps this isn't the best forum to post such a blast as this, but its
intent at least is well meant.
Paul Wolfson, Ph.D.
Principal and President
Process and System Integration, Inc.
PO Box 118524
Carrollton, TX 75011-8524
----- Original Message -----
From: "McFadden, Ken" <ken.mcfadden@lmco.com>
To: "'Russell Coker'" <russell@coker.com.au>; "JW" <jw@centraltexasit.com>;
"SE Linux" <selinux@tycho.nsa.gov>
Cc: "Haigh, Tom" <tom_haigh@securecomputing.com>; "'Admissions Office'"
<admissions@internet.edu.nf>; "Carsten Grohmann"
<carsten.grohmann@dr-baldeweg.de>
Sent: Tuesday, June 04, 2002 5:28 PM
Subject: RE: Sorry, read this one: Re: SELinux Dumb Questions
> Once again, We are doing this for NSA and GNU NOT SECURE COMPUTING!!!!!!!
> If Tom has a problem <<snip>> treat it as GNU per NSA's web page!!!!!!!
>
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 8+ messages in thread* Re: Outside observer comments
2002-06-05 2:43 ` Outside observer comments Paul Wolfson
@ 2002-06-05 3:14 ` Russell Coker
2002-06-05 4:07 ` JW
2002-06-05 7:29 ` Tom
2 siblings, 0 replies; 8+ messages in thread
From: Russell Coker @ 2002-06-05 3:14 UTC (permalink / raw)
To: Paul Wolfson, McFadden, Ken, JW, SE Linux
Cc: Haigh, Tom, 'Admissions Office', Carsten Grohmann,
Paul Wolfson
On Wed, 5 Jun 2002 04:43, Paul Wolfson wrote:
> I recently added myself to the SELinux listserver because of genuine shared
> concerns about securing open source computing. NSA is correct to be doing
> this initiative and linux in its evolution will be better for it.
>
> Now, from the few dozen emails that have come across my screen are any
> indication, bickering is counter-productive. It resembles government
This is not bickering. This is about a commercial organization threatening
action which would permanently prevent me from doing any SE Linux work. This
is not a minor issue.
> procurement at its worst. In that atmosphere I am afraid that there is
> little that I will be able to contribute. My company, is relatively new,
> but has principal engineers who hold or have held DoD clearance at TS and
> higher and would be interested in contributing to this effort. If someone
> on this list is a good POC let me know and perhaps we will be in a position
> to help.
>
> Perhaps this isn't the best forum to post such a blast as this, but its
> intent at least is well meant.
It's probably best to read more than a dozen messages before making
judgements. The last time there was any serious debate on this list was when
we were discussing /usr/local last year.
> ----- Original Message -----
> From: "McFadden, Ken" <ken.mcfadden@lmco.com>
> To: "'Russell Coker'" <russell@coker.com.au>; "JW" <jw@centraltexasit.com>;
> "SE Linux" <selinux@tycho.nsa.gov>
> Cc: "Haigh, Tom" <tom_haigh@securecomputing.com>; "'Admissions Office'"
> <admissions@internet.edu.nf>; "Carsten Grohmann"
> <carsten.grohmann@dr-baldeweg.de>
> Sent: Tuesday, June 04, 2002 5:28 PM
> Subject: RE: Sorry, read this one: Re: SELinux Dumb Questions
>
> > Once again, We are doing this for NSA and GNU NOT SECURE COMPUTING!!!!!!!
> > If Tom has a problem <<snip>> treat it as GNU per NSA's web page!!!!!!!
--
I do not get viruses because I do not use MS software.
If you use Outlook then please do not put my email address in your
address-book so that WHEN you get a virus it won't use my address in the
>From field.
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: Outside observer comments
2002-06-05 2:43 ` Outside observer comments Paul Wolfson
2002-06-05 3:14 ` Russell Coker
@ 2002-06-05 4:07 ` JW
2002-06-05 4:28 ` Russell Coker
2002-06-05 7:29 ` Tom
2 siblings, 1 reply; 8+ messages in thread
From: JW @ 2002-06-05 4:07 UTC (permalink / raw)
To: SE Linux
On Tuesday 04 June 2002 09:43 pm, you wrote:
> Hello,
>
> I recently added myself to the SELinux listserver because of genuine shared
> concerns about securing open source computing.
Your very message would suggest that you have no idea what Open Source is all
about.
I strongly suggest you go read the following:
http://www.opensource.org/docs/definition.html (and all of
http://www.opensource.org/, really)
http://www.gnu.org/philosophy/free-sw.html
http://www.gnu.org/copyleft/copyleft.html
> NSA is correct to be doing
> this initiative and linux in its evolution will be better for it.
Yes, but that is not the issue. The issue is a third party is claiming patent
and licensing rights over GPLd code.
> Now, from the few dozen emails that have come across my screen are any
> indication, bickering is counter-productive.
That is only your opinion; and we are not bikering, we are asking for solid
clarification of a bad situation. If Secure Computing is correct, then all
work on SE-Linux to date is actually illegal, because non-Free work was
mistakenly published under the GPL (if secure computing is correct), and that
is not legal (you cannot publish non-free work under a Free license such as
the GPL).
Additionally, if Secure Computing is correct, it would suggest that whoever
put the SE-Linux code under the GPL did not have the legal rights to do so
(You can't publish as "Free" code/ideas that you are not the author of).
> It resembles government
> procurement at its worst.
No, it resembles citizens defending themselves against corporate or
governmental tyranny, and clarification of who's lying and who's not. The NSA
and Secure Computing are saying 3 different things. Until today, everyone has
been belive the NSA. Either Secure Computing or the NSA is dead wrong, and we
need to know which one very soon, as it has serious implications either way.
I am sure people who have contributed code to SE-Linux under the assumption
that the NSA was telling the truth when they stated SE-Linux was Free are not
going to be very happy to find that they have been deceived, and will
probably want to retract thier contributions, which they have copyright
ownership over.
> In that atmosphere I am afraid that there is
> little that I will be able to contribute.
You don't seem to understand what a serious matter this is anyway,
and contributing to a project without understanding it is a very bad idea.
For your own sake, it is just as well that you not contribute.
> Perhaps this isn't the best forum to post such a blast as this, but its
> intent at least is well meant.
I appreciate your (no doubt) well-intended yet sadly misinformed message.
Hopefully you will understand it all better in the future. I really do
suggest you go read the URLs I mentioned above before attempting to
contribute to a Free Software project. To do so without understanding what
you are doing is not wise.
JW
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: Outside observer comments
2002-06-05 4:07 ` JW
@ 2002-06-05 4:28 ` Russell Coker
0 siblings, 0 replies; 8+ messages in thread
From: Russell Coker @ 2002-06-05 4:28 UTC (permalink / raw)
To: jw, SE Linux
On Wed, 5 Jun 2002 06:07, JW wrote:
> implications either way. I am sure people who have contributed code to
> SE-Linux under the assumption that the NSA was telling the truth when they
> stated SE-Linux was Free are not going to be very happy to find that they
> have been deceived, and will probably want to retract thier contributions,
> which they have copyright ownership over.
Such contributions can't be retracted. However contributions to a GPL
project can't be used in a non-GPL fashion without explicit authorisation,
such authorisation won't be forthcoming for my work - so it will be used
under the GPL or not at all.
Also if SE Linux was made non-free and people wrote non-free SE code that
closely resembled GPL SE code then a copyright infringement suit could
follow...
> > In that atmosphere I am afraid that there is
> > little that I will be able to contribute.
>
> You don't seem to understand what a serious matter this is anyway,
> and contributing to a project without understanding it is a very bad idea.
> For your own sake, it is just as well that you not contribute.
Let's not get nasty. Breaching the rule of reading a list well before
posting is a bad thing, but let's not flame them excessively.
--
I do not get viruses because I do not use MS software.
If you use Outlook then please do not put my email address in your
address-book so that WHEN you get a virus it won't use my address in the
>From field.
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: Outside observer comments
2002-06-05 2:43 ` Outside observer comments Paul Wolfson
2002-06-05 3:14 ` Russell Coker
2002-06-05 4:07 ` JW
@ 2002-06-05 7:29 ` Tom
2 siblings, 0 replies; 8+ messages in thread
From: Tom @ 2002-06-05 7:29 UTC (permalink / raw)
To: SE Linux
On Tue, Jun 04, 2002 at 09:43:16PM -0500, Paul Wolfson wrote:
> Now, from the few dozen emails that have come across my screen are any
> indication, bickering is counter-productive.
For all the time I've been on this list, this has been a one-time
flare. You probably joined at a bad moment, since everything else on
the list was very productive.
That said, the patent/license issue *is* a serious problem.
--
New GPG Key issued (old key expired):
http://web.lemuria.org/pubkey.html
pub 1024D/2D7A04F5 2002-05-16 Tom Vogt <tom@lemuria.org>
Key fingerprint = C731 64D1 4BCF 4C20 48A4 29B2 BF01 9FA1 2D7A 04F5
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2002-06-05 7:29 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-06-04 23:37 SELinux Dumb Questions Roland.Jones
2002-06-05 4:26 ` Ed Street
2002-06-05 5:34 ` Outside Observer Comments Paul Wolfson
-- strict thread matches above, loose matches on Subject: below --
2002-06-04 22:28 Sorry, read this one: Re: SELinux Dumb Questions McFadden, Ken
2002-06-05 2:43 ` Outside observer comments Paul Wolfson
2002-06-05 3:14 ` Russell Coker
2002-06-05 4:07 ` JW
2002-06-05 4:28 ` Russell Coker
2002-06-05 7:29 ` Tom
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.