All of lore.kernel.org
 help / color / mirror / Atom feed
* FW: Current/Future Plans to Support Stacking LSM Modules
@ 2007-01-16 19:41 Tom Fortmann
  2007-01-16 19:52 ` Stephen Smalley
  0 siblings, 1 reply; 9+ messages in thread
From: Tom Fortmann @ 2007-01-16 19:41 UTC (permalink / raw)
  To: selinux

Can you send me a pointer to the limited stacking that selinux supports?

I will join the LSM list.  I started here because LSM already supports a
basic stacking method.  However, SELinux does not support the
mod_reg_security call necessary to take advantage of this capability.  

The product we are developing adds additional security at the application
data layer.  It is a commercial product so I can't say a lot, other then to
say that SELinux currently does not provide the additional features we are
working on.

Thomas Fortmann
Sr. Software Engineer
Xcape Solutions, Inc.

-----Original Message-----
From: owner-selinux@tycho.nsa.gov [mailto:owner-selinux@tycho.nsa.gov] On
Behalf Of Casey Schaufler
Sent: Tuesday, January 16, 2007 12:46 PM
To: Tom Fortmann; selinux@tycho.nsa.gov
Cc: linux-security-module@vger.kernel.org
Subject: Re: Current/Future Plans to Support Stacking LSM Modules


--- Tom Fortmann <tfortmann@xcapesolutions.net> wrote:

> Are their any current or future plans to support
> stacking additional
> security modules on the LSM interface?

It has certainly been considered from
time to time. David Wheeler's early work
came pretty close.

> Alternatively, are there any current or future plans
> to allow the SELinux
> framework to be expanded with third party loadable
> modules?

SELinux does currently, although somewhat
begrudgingly, allow limited stacking in
support of a particular set of modules. 

It wasn't but a year ago that the SELinux
community was arguing that LSM ought to be
dispensed with, as they argued that:
  - No one else was using LSM
  - SELinux does everything that a rational
    being might want done anyway.

> We are working on some enhanced security solutions
> that require access to
> the LSM interface, but we do not want to preclude
> the use of SELinux by our
> customers.

You might take this onto the LSM list (I've
added it to the CC here) as there are a (very)
few people who follow LSM that do not subscribe
here.

Just out of curiosity, what's your module
going to do?


Casey Schaufler
casey@schaufler-ca.com

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov
with
the words "unsubscribe selinux" without quotes as the message.


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2007-01-19 15:56 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-01-16 19:41 FW: Current/Future Plans to Support Stacking LSM Modules Tom Fortmann
2007-01-16 19:52 ` Stephen Smalley
2007-01-16 20:31   ` Tom Fortmann
2007-01-16 20:31   ` Casey Schaufler
2007-01-17 20:09   ` Tom Fortmann
2007-01-18 12:48     ` Stephen Smalley
2007-01-18 17:13       ` Tom Fortmann
2007-01-19 15:31         ` Stephen Smalley
2007-01-19 15:57           ` Tom Fortmann

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.