* SE-Linux on SuSE
@ 2002-05-28 16:11 JW
2002-06-03 10:23 ` Carsten Grohmann
0 siblings, 1 reply; 18+ messages in thread
From: JW @ 2002-05-28 16:11 UTC (permalink / raw)
To: SeLinux
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hello,
I am interested in running SE-Linux on SuSE.
I'd appreciate hearing from anyone who's tried it.
Esp. how hard/easy it was to install/configure, anything special you had to do to get it working, and what you like/dislike about it now that you have it working.
Thanks.
- --
- ----------------------------------------------------
Jonathan Wilson
System Administrator
Cedar Creek Software http://www.cedarcreeksoftware.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
iD8DBQE886w7Q5u80xXOLBcRAu2FAKCr7p8g97WTxT3d+M5fVSK5B5hupQCfWu+k
6BRs3lkJBbb9x3Se9q20wnw=
=IkW0
-----END PGP SIGNATURE-----
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* Re: SE-Linux on SuSE
2002-05-28 16:11 SE-Linux on SuSE JW
@ 2002-06-03 10:23 ` Carsten Grohmann
2002-06-03 14:50 ` SELinux Dumb Questions Admissions Office
0 siblings, 1 reply; 18+ messages in thread
From: Carsten Grohmann @ 2002-06-03 10:23 UTC (permalink / raw)
To: jw, selinux
Hi Jonathan!
I've install SE-Linux on SuSE (7.1). It is easy to install. You should
run it a few days in the permissive mode to add a few new rules e.g. to
add the blogd to the initrc domain. And you should remove a lot of cron
jobs, if you like or you write rules for this jobs. And the mingettys,
but SE-Linux works fine on SuSE too.
Carsten
JW schrieb:
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Hello,
>
> I am interested in running SE-Linux on SuSE.
>
> I'd appreciate hearing from anyone who's tried it.
>
> Esp. how hard/easy it was to install/configure, anything special you had to do to get it working, and what you like/dislike about it now that you have it working.
>
> Thanks.
> - --
>
> - ----------------------------------------------------
> Jonathan Wilson
> System Administrator
> Cedar Creek Software http://www.cedarcreeksoftware.com
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* Re: SELinux Dumb Questions
2002-06-03 10:23 ` Carsten Grohmann
@ 2002-06-03 14:50 ` Admissions Office
2002-06-03 15:39 ` Russell Coker
0 siblings, 1 reply; 18+ messages in thread
From: Admissions Office @ 2002-06-03 14:50 UTC (permalink / raw)
To: Carsten Grohmann, jw, selinux
Folks this may seem like a dumb question given the Open Source and postings
on the site. Its just that we want to be sure....
Is there any reason why a Colo company cannot offer SELinux as a standard
product offering they would install on clients servers?
That's all. I try to limit my dumb questions.
Ian McBeth
Sys Admin
----- Original Message -----
From: "Carsten Grohmann" <carsten.grohmann@dr-baldeweg.de>
To: <jw@centraltexasit.com>; <selinux@tycho.nsa.gov>
Sent: Monday, June 03, 2002 04:23
Subject: Re: SE-Linux on SuSE
> Hi Jonathan!
>
> I've install SE-Linux on SuSE (7.1). It is easy to install. You should
> run it a few days in the permissive mode to add a few new rules e.g. to
> add the blogd to the initrc domain. And you should remove a lot of cron
> jobs, if you like or you write rules for this jobs. And the mingettys,
> but SE-Linux works fine on SuSE too.
>
> Carsten
>
> JW schrieb:
> >
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA1
> >
> > Hello,
> >
> > I am interested in running SE-Linux on SuSE.
> >
> > I'd appreciate hearing from anyone who's tried it.
> >
> > Esp. how hard/easy it was to install/configure, anything special you had
to do to get it working, and what you like/dislike about it now that you
have it working.
> >
> > Thanks.
> > - --
> >
> > - ----------------------------------------------------
> > Jonathan Wilson
> > System Administrator
> > Cedar Creek Software http://www.cedarcreeksoftware.com
>
> --
> You have received this message because you are subscribed to the selinux
list.
> If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov
with
> the words "unsubscribe selinux" without quotes as the message.
>
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* Re: SELinux Dumb Questions
2002-06-03 14:50 ` SELinux Dumb Questions Admissions Office
@ 2002-06-03 15:39 ` Russell Coker
2002-06-03 17:50 ` Mirror Offer Admissions Office
2002-06-04 21:30 ` SELinux Dumb Questions JW
0 siblings, 2 replies; 18+ messages in thread
From: Russell Coker @ 2002-06-03 15:39 UTC (permalink / raw)
To: Admissions Office; +Cc: SE Linux
On Mon, 3 Jun 2002 16:50, Admissions Office wrote:
> Folks this may seem like a dumb question given the Open Source and postings
> on the site. Its just that we want to be sure....
>
> Is there any reason why a Colo company cannot offer SELinux as a standard
> product offering they would install on clients servers?
As Mark stated there are no license or legal issues preventing such use.
In fact SE Linux is very desirable as an option for a hosting company as it
allows safer sharing of recources. I believe that the requirements that JW
plans to solve with SE Linux are along the lines of partitioning a server for
several users (who don't necessarily trust each other and aren't trusted by
the administrator) to bind to ports <1024.
Of course as a practical measure you probably want to offer a non-SE service
too, people get paranoid when the NSA is mentioned and some customers will
probably pay extra to have a dedicated server without NSA software rather
than a shared server with the NSA software...
--
I do not get viruses because I do not use MS software.
If you use Outlook then please do not put my email address in your
address-book so that WHEN you get a virus it won't use my address in the
>From field.
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* Mirror Offer
2002-06-03 15:39 ` Russell Coker
@ 2002-06-03 17:50 ` Admissions Office
2002-06-03 18:45 ` Russell Coker
2002-06-03 19:10 ` Stephen Smalley
2002-06-04 21:30 ` SELinux Dumb Questions JW
1 sibling, 2 replies; 18+ messages in thread
From: Admissions Office @ 2002-06-03 17:50 UTC (permalink / raw)
To: Russell Coker; +Cc: SE Linux
Mirror: Offer
One of my technical people wants me to ask if you would like the software to
be avail. on a mirror on our site. People just keep asking our staff about
it since I 'opened my mouth.' We have large bandwidth and would be happy to
mirror it, Yes I know we can anyway but, its nice to have the group / all
involved agree. Our servers can handle the load and the bandwidth!
Ian McBeth
----- Original Message -----
From: "Russell Coker" <russell@coker.com.au>
To: "Admissions Office" <admissions@internet.edu.nf>
Cc: "SE Linux" <selinux@tycho.nsa.gov>
Sent: Monday, June 03, 2002 09:39
Subject: Re: SELinux Dumb Questions
> On Mon, 3 Jun 2002 16:50, Admissions Office wrote:
> > Folks this may seem like a dumb question given the Open Source and
postings
> > on the site. Its just that we want to be sure....
> >
> > Is there any reason why a Colo company cannot offer SELinux as a
standard
> > product offering they would install on clients servers?
>
> As Mark stated there are no license or legal issues preventing such use.
>
> In fact SE Linux is very desirable as an option for a hosting company as
it
> allows safer sharing of recources. I believe that the requirements that
JW
> plans to solve with SE Linux are along the lines of partitioning a server
for
> several users (who don't necessarily trust each other and aren't trusted
by
> the administrator) to bind to ports <1024.
>
> Of course as a practical measure you probably want to offer a non-SE
service
> too, people get paranoid when the NSA is mentioned and some customers will
> probably pay extra to have a dedicated server without NSA software rather
> than a shared server with the NSA software...
>
> --
> I do not get viruses because I do not use MS software.
> If you use Outlook then please do not put my email address in your
> address-book so that WHEN you get a virus it won't use my address in the
> >From field.
>
> --
> You have received this message because you are subscribed to the selinux
list.
> If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov
with
> the words "unsubscribe selinux" without quotes as the message.
>
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* Re: Mirror Offer
2002-06-03 17:50 ` Mirror Offer Admissions Office
@ 2002-06-03 18:45 ` Russell Coker
2002-06-03 19:10 ` Stephen Smalley
1 sibling, 0 replies; 18+ messages in thread
From: Russell Coker @ 2002-06-03 18:45 UTC (permalink / raw)
To: Admissions Office; +Cc: SE Linux
On Mon, 3 Jun 2002 19:50, Admissions Office wrote:
> One of my technical people wants me to ask if you would like the software
> to be avail. on a mirror on our site. People just keep asking our staff
> about it since I 'opened my mouth.' We have large bandwidth and would be
> happy to mirror it, Yes I know we can anyway but, its nice to have the
> group / all involved agree. Our servers can handle the load and the
> bandwidth!
You can mirror my packages from http://www.coker.com.au/selinux/ if you want,
but I doubt that it's any great benefit for anyone. The bandwidth used isn't
enough to be an issue for my provier and the files aren't large enough for
anyone to really complain about download speed.
As for the main NSA site, you'll have to wait for an answer from them, I
suspect that they would prefer to have it downloaded from them directly
though.
--
I do not get viruses because I do not use MS software.
If you use Outlook then please do not put my email address in your
address-book so that WHEN you get a virus it won't use my address in the
>From field.
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* Re: Mirror Offer
2002-06-03 17:50 ` Mirror Offer Admissions Office
2002-06-03 18:45 ` Russell Coker
@ 2002-06-03 19:10 ` Stephen Smalley
2002-06-03 19:16 ` Admissions Office
1 sibling, 1 reply; 18+ messages in thread
From: Stephen Smalley @ 2002-06-03 19:10 UTC (permalink / raw)
To: Admissions Office; +Cc: Russell Coker, SE Linux
On Mon, 3 Jun 2002, Admissions Office wrote:
> One of my technical people wants me to ask if you would like the software to
> be avail. on a mirror on our site. People just keep asking our staff about
> it since I 'opened my mouth.' We have large bandwidth and would be happy to
> mirror it, Yes I know we can anyway but, its nice to have the group / all
> involved agree. Our servers can handle the load and the bandwidth!
This topic has come up previously on the list; please see the archives.
The answer has always been that people are free to mirror the site if
they wish, but the NSA doesn't support "official" mirrors.
There is at least one "unofficial" mirror maintained in Australia at
wiretapped.net. There is also the sourceforge CVS tree.
--
Stephen D. Smalley, NAI Labs
ssmalley@nai.com
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* Re: Mirror Offer
2002-06-03 19:10 ` Stephen Smalley
@ 2002-06-03 19:16 ` Admissions Office
0 siblings, 0 replies; 18+ messages in thread
From: Admissions Office @ 2002-06-03 19:16 UTC (permalink / raw)
To: Stephen Smalley; +Cc: Russell Coker, SE Linux
Ok, then we will start an un-official mirror here in Canada.
Details to follow::::::: any suggestion you have would be noted.
Ian
----- Original Message -----
From: "Stephen Smalley" <sds@tislabs.com>
To: "Admissions Office" <admissions@internet.edu.nf>
Cc: "Russell Coker" <russell@coker.com.au>; "SE Linux"
<selinux@tycho.nsa.gov>
Sent: Monday, June 03, 2002 13:10
Subject: Re: Mirror Offer
>
> On Mon, 3 Jun 2002, Admissions Office wrote:
>
> > One of my technical people wants me to ask if you would like the
software to
> > be avail. on a mirror on our site. People just keep asking our staff
about
> > it since I 'opened my mouth.' We have large bandwidth and would be
happy to
> > mirror it, Yes I know we can anyway but, its nice to have the group /
all
> > involved agree. Our servers can handle the load and the bandwidth!
>
> This topic has come up previously on the list; please see the archives.
> The answer has always been that people are free to mirror the site if
> they wish, but the NSA doesn't support "official" mirrors.
>
> There is at least one "unofficial" mirror maintained in Australia at
> wiretapped.net. There is also the sourceforge CVS tree.
>
> --
> Stephen D. Smalley, NAI Labs
> ssmalley@nai.com
>
>
>
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* Re: SELinux Dumb Questions
2002-06-03 15:39 ` Russell Coker
2002-06-03 17:50 ` Mirror Offer Admissions Office
@ 2002-06-04 21:30 ` JW
2002-06-04 21:59 ` Russell Coker
2002-06-05 1:30 ` SELinux Dumb Questions Admissions Office
1 sibling, 2 replies; 18+ messages in thread
From: JW @ 2002-06-04 21:30 UTC (permalink / raw)
To: selinux
Cc: Haigh, Tom, 'Admissions Office', Carsten Grohmann,
Russell Coker
> On Mon, 3 Jun 2002 16:50, Admissions Office wrote:
> > Folks this may seem like a dumb question given the Open Source and
> > postings on the site. Its just that we want to be sure....
> >
> > Is there any reason why a Colo company cannot offer SELinux as a standard
> > product offering they would install on clients servers?
> As Mark stated there are no license or legal issues preventing such use.
On Monday 03 June 2002 04:13 pm, Haigh, Tom wrote:
> SELinux includes Type Enforcement technology developed and patented by the
> Secure Computing Corporation, who still holds rights to all commercial use
> of the technology. Before a colo company, or anyone else uses the
> technology commercially, it will be necessary to negotiate a license with
> Secure Computing. If anyone wants to do so, I can help get the ball
> rolling with our Legal and BD folks.
>
> --Tom
>
> Dr. Tom Haigh, CTO
> Secure Computing Corp.
> 2675 Long Lake Road
> Roseville, MN 55113
>
> 651-628-2738 (V)
> 651-628-2701 (F)
>
> haigh@securecomputing.com
>
>
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* Re: SELinux Dumb Questions
2002-06-04 21:30 ` SELinux Dumb Questions JW
@ 2002-06-04 21:59 ` Russell Coker
2002-06-05 0:58 ` Dale Amon
[not found] ` <200206042255.g54MtHu1003846@turing-police.cc.vt.edu>
2002-06-05 1:30 ` SELinux Dumb Questions Admissions Office
1 sibling, 2 replies; 18+ messages in thread
From: Russell Coker @ 2002-06-04 21:59 UTC (permalink / raw)
To: jw, selinux
Cc: Haigh, Tom, 'Admissions Office', Carsten Grohmann,
linux-security-module
On Tue, 4 Jun 2002 23:30, JW wrote:
> > On Mon, 3 Jun 2002 16:50, Admissions Office wrote:
> > > Folks this may seem like a dumb question given the Open Source and
> > > postings on the site. Its just that we want to be sure....
> > >
> > > Is there any reason why a Colo company cannot offer SELinux as a
> > > standard product offering they would install on clients servers?
> >
> > As Mark stated there are no license or legal issues preventing such use.
>
> On Monday 03 June 2002 04:13 pm, Haigh, Tom wrote:
> > SELinux includes Type Enforcement technology developed and patented by
> > the Secure Computing Corporation, who still holds rights to all
> > commercial use of the technology. Before a colo company, or anyone else
> > uses the technology commercially, it will be necessary to negotiate a
> > license with Secure Computing. If anyone wants to do so, I can help get
> > the ball rolling with our Legal and BD folks.
Let's look at the following URL:
http://www.securecomputing.com/archive/press/2000/nsa_faq_secure_linux.html
> Question 6: Will SCC use its patent on Type Enforcement TM to restrict use,
> future development, derivative work, or release of the source code of the
> system?
>
> There will be no restrictions on the use of TE by the Linux open source
> community. We believe that leveraging the resources of the Linux community
> is the best way to develop robust security for Linux.
That seems like a clear statement that we can do what we like with it!
But Tom, if your company does want to go ahead with this patent plan then
please do the following:
1) Change that misleading web page.
2) Let me know so I can remove all SE Linux code from Debian, remove it from
my client's machines, and start work on a competing product.
3) Make formal statements as to limitations of distribution etc, also
clarify to what extent you want SE Linux code removed from the world. Should
I get the upstream maintainer of stat to remove the SE Linux code too? Also
you'll have to get it removed from LSM which is under the GPL, and you had
better hope that the problems with building as a module are fixed quickly -
you can't ship code that links with the kernel unless it's under the GPL.
PS When does the patent expire? If it's due to expire in 1 year or less we
can just wait until it's gone...
--
I do not get viruses because I do not use MS software.
If you use Outlook then please do not put my email address in your
address-book so that WHEN you get a virus it won't use my address in the
>From field.
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread* Re: SELinux Dumb Questions
2002-06-04 21:59 ` Russell Coker
@ 2002-06-05 0:58 ` Dale Amon
[not found] ` <200206042255.g54MtHu1003846@turing-police.cc.vt.edu>
1 sibling, 0 replies; 18+ messages in thread
From: Dale Amon @ 2002-06-05 0:58 UTC (permalink / raw)
To: Russell Coker
Cc: jw, selinux, Haigh, Tom, 'Admissions Office',
Carsten Grohmann, linux-security-module
On Tue, Jun 04, 2002 at 11:59:46PM +0200, Russell Coker wrote:
> > On Monday 03 June 2002 04:13 pm, Haigh, Tom wrote:
> > > SELinux includes Type Enforcement technology developed and patented by
> > > the Secure Computing Corporation, who still holds rights to all
> > > commercial use of the technology. Before a colo company, or anyone else
> > > uses the technology commercially, it will be necessary to negotiate a
> > > license with Secure Computing. If anyone wants to do so, I can help get
> > > the ball rolling with our Legal and BD folks.
>
> PS When does the patent expire? If it's due to expire in 1 year or less we
> can just wait until it's gone...
I agree with Russell. This really had better be clarified. I believe it
is the intent of many on this list, myself included, to productize
systems based on SELinux.
It's either GPL or it ain't. Which is it? Do I drop my plans or continue?
PS: For my purposes, the BSD license will do just as well.
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread[parent not found: <200206042255.g54MtHu1003846@turing-police.cc.vt.edu>]
* Re: SELinux Dumb Questions
2002-06-04 21:30 ` SELinux Dumb Questions JW
2002-06-04 21:59 ` Russell Coker
@ 2002-06-05 1:30 ` Admissions Office
1 sibling, 0 replies; 18+ messages in thread
From: Admissions Office @ 2002-06-05 1:30 UTC (permalink / raw)
To: jw, selinux; +Cc: Haigh, Tom, Carsten Grohmann, Russell Coker
Sorry - I did not mean to cause a storm..... Before we know it the CIA will
ask for Inter-agency cooperation :-)
Serious - My firneds and yes colo clients ask if we will "help" them install
and or maintain this OS. Its said, the Open GL Ec so what a dummy. I just
asked. Please - develop, forget me. We can and will work this out. The
world has bigger problems.
Joop Cousteau
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* RE: SELinux Dumb Questions
@ 2002-06-03 15:00 Westerman, Mark
2002-06-03 15:34 ` Admissions Office
0 siblings, 1 reply; 18+ messages in thread
From: Westerman, Mark @ 2002-06-03 15:00 UTC (permalink / raw)
To: 'Admissions Office', selinux
None
> -----Original Message-----
> From: Admissions Office [mailto:admissions@internet.edu.nf]
> Sent: Monday, June 03, 2002 9:51 AM
> To: Carsten Grohmann; jw@centraltexasit.com; selinux@tycho.nsa.gov
> Subject: Re: SELinux Dumb Questions
>
>
> Folks this may seem like a dumb question given the Open
> Source and postings
> on the site. Its just that we want to be sure....
>
> Is there any reason why a Colo company cannot offer SELinux
> as a standard
> product offering they would install on clients servers?
>
> That's all. I try to limit my dumb questions.
>
> Ian McBeth
> Sys Admin
>
>
> ----- Original Message -----
> From: "Carsten Grohmann" <carsten.grohmann@dr-baldeweg.de>
> To: <jw@centraltexasit.com>; <selinux@tycho.nsa.gov>
> Sent: Monday, June 03, 2002 04:23
> Subject: Re: SE-Linux on SuSE
>
>
> > Hi Jonathan!
> >
> > I've install SE-Linux on SuSE (7.1). It is easy to install.
> You should
> > run it a few days in the permissive mode to add a few new
> rules e.g. to
> > add the blogd to the initrc domain. And you should remove a
> lot of cron
> > jobs, if you like or you write rules for this jobs. And the
> mingettys,
> > but SE-Linux works fine on SuSE too.
> >
> > Carsten
> >
> > JW schrieb:
> > >
> > > -----BEGIN PGP SIGNED MESSAGE-----
> > > Hash: SHA1
> > >
> > > Hello,
> > >
> > > I am interested in running SE-Linux on SuSE.
> > >
> > > I'd appreciate hearing from anyone who's tried it.
> > >
> > > Esp. how hard/easy it was to install/configure, anything
> special you had
> to do to get it working, and what you like/dislike about it
> now that you
> have it working.
> > >
> > > Thanks.
> > > - --
> > >
> > > - ----------------------------------------------------
> > > Jonathan Wilson
> > > System Administrator
> > > Cedar Creek Software http://www.cedarcreeksoftware.com
> >
> > --
> > You have received this message because you are subscribed
> to the selinux
> list.
> > If you no longer wish to subscribe, send mail to
> majordomo@tycho.nsa.gov
> with
> > the words "unsubscribe selinux" without quotes as the message.
> >
>
>
> --
> You have received this message because you are subscribed to
> the selinux list.
> If you no longer wish to subscribe, send mail to
> majordomo@tycho.nsa.gov with
> the words "unsubscribe selinux" without quotes as the message.
>
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* Re: SELinux Dumb Questions
2002-06-03 15:00 Westerman, Mark
@ 2002-06-03 15:34 ` Admissions Office
0 siblings, 0 replies; 18+ messages in thread
From: Admissions Office @ 2002-06-03 15:34 UTC (permalink / raw)
To: Westerman, Mark, selinux
Thanks to All. We would not says SELinux offered by the NSA ! People have
really been asking about it once we tell them such a thing exists. Many are
just interested so we point them to the site. Our mission would be to start
providing support to clients who ask for it.
Again, thanks to all...
----- Original Message -----
From: "Westerman, Mark" <Mark.Westerman@csoconline.com>
To: "'Admissions Office'" <admissions@internet.edu.nf>;
<selinux@tycho.nsa.gov>
Sent: Monday, June 03, 2002 09:00
Subject: RE: SELinux Dumb Questions
> None
>
> > -----Original Message-----
> > From: Admissions Office [mailto:admissions@internet.edu.nf]
> > Sent: Monday, June 03, 2002 9:51 AM
> > To: Carsten Grohmann; jw@centraltexasit.com; selinux@tycho.nsa.gov
> > Subject: Re: SELinux Dumb Questions
> >
> >
> > Folks this may seem like a dumb question given the Open
> > Source and postings
> > on the site. Its just that we want to be sure....
> >
> > Is there any reason why a Colo company cannot offer SELinux
> > as a standard
> > product offering they would install on clients servers?
> >
> > That's all. I try to limit my dumb questions.
> >
> > Ian McBeth
> > Sys Admin
> >
> >
> > ----- Original Message -----
> > From: "Carsten Grohmann" <carsten.grohmann@dr-baldeweg.de>
> > To: <jw@centraltexasit.com>; <selinux@tycho.nsa.gov>
> > Sent: Monday, June 03, 2002 04:23
> > Subject: Re: SE-Linux on SuSE
> >
> >
> > > Hi Jonathan!
> > >
> > > I've install SE-Linux on SuSE (7.1). It is easy to install.
> > You should
> > > run it a few days in the permissive mode to add a few new
> > rules e.g. to
> > > add the blogd to the initrc domain. And you should remove a
> > lot of cron
> > > jobs, if you like or you write rules for this jobs. And the
> > mingettys,
> > > but SE-Linux works fine on SuSE too.
> > >
> > > Carsten
> > >
> > > JW schrieb:
> > > >
> > > > -----BEGIN PGP SIGNED MESSAGE-----
> > > > Hash: SHA1
> > > >
> > > > Hello,
> > > >
> > > > I am interested in running SE-Linux on SuSE.
> > > >
> > > > I'd appreciate hearing from anyone who's tried it.
> > > >
> > > > Esp. how hard/easy it was to install/configure, anything
> > special you had
> > to do to get it working, and what you like/dislike about it
> > now that you
> > have it working.
> > > >
> > > > Thanks.
> > > > - --
> > > >
> > > > - ----------------------------------------------------
> > > > Jonathan Wilson
> > > > System Administrator
> > > > Cedar Creek Software http://www.cedarcreeksoftware.com
> > >
> > > --
> > > You have received this message because you are subscribed
> > to the selinux
> > list.
> > > If you no longer wish to subscribe, send mail to
> > majordomo@tycho.nsa.gov
> > with
> > > the words "unsubscribe selinux" without quotes as the message.
> > >
> >
> >
> > --
> > You have received this message because you are subscribed to
> > the selinux list.
> > If you no longer wish to subscribe, send mail to
> > majordomo@tycho.nsa.gov with
> > the words "unsubscribe selinux" without quotes as the message.
> >
>
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* RE: SELinux Dumb Questions
@ 2002-06-04 23:37 Roland.Jones
2002-06-05 4:26 ` Ed Street
0 siblings, 1 reply; 18+ messages in thread
From: Roland.Jones @ 2002-06-04 23:37 UTC (permalink / raw)
To: russell, jw, selinux
Cc: tom_haigh, admissions, carsten.grohmann, linux-security-module
Russell,
Your comments and clarifications are most enlightening and reflect my under standing of SELinux's use as open source code. I find this issue of private licensing confusing since I thought the whole idea was to get this technology into the community. The NSA's SELinux overview says the following at the end of the page:
Security-enhanced Linux is being released under the same terms and conditions as the original sources. The release includes documentation and source code for both the system and some system utilities that were modified to make use of the new features. Participation with comments, constructive criticism, and/or improvements is welcome.
It doesn't seem to me that NSA's intention was to restrict the deployment of this technology when they released SELinux. Any NSA types out there?
Roland
-----Original Message-----
From: ext Russell Coker [mailto:russell@coker.com.au]
Sent: Tuesday, June 04, 2002 3:00 PM
To: jw@centraltexasit.com; selinux@tycho.nsa.gov
Cc: Haigh, Tom; 'Admissions Office'; Carsten Grohmann;
linux-security-module@wirex.com
Subject: Re: SELinux Dumb Questions
On Tue, 4 Jun 2002 23:30, JW wrote:
> > On Mon, 3 Jun 2002 16:50, Admissions Office wrote:
> > > Folks this may seem like a dumb question given the Open Source and
> > > postings on the site. Its just that we want to be sure....
> > >
> > > Is there any reason why a Colo company cannot offer SELinux as a
> > > standard product offering they would install on clients servers?
> >
> > As Mark stated there are no license or legal issues preventing such use.
>
> On Monday 03 June 2002 04:13 pm, Haigh, Tom wrote:
> > SELinux includes Type Enforcement technology developed and patented by
> > the Secure Computing Corporation, who still holds rights to all
> > commercial use of the technology. Before a colo company, or anyone else
> > uses the technology commercially, it will be necessary to negotiate a
> > license with Secure Computing. If anyone wants to do so, I can help get
> > the ball rolling with our Legal and BD folks.
Let's look at the following URL:
http://www.securecomputing.com/archive/press/2000/nsa_faq_secure_linux.html
> Question 6: Will SCC use its patent on Type Enforcement TM to restrict use,
> future development, derivative work, or release of the source code of the
> system?
>
> There will be no restrictions on the use of TE by the Linux open source
> community. We believe that leveraging the resources of the Linux community
> is the best way to develop robust security for Linux.
That seems like a clear statement that we can do what we like with it!
But Tom, if your company does want to go ahead with this patent plan then
please do the following:
1) Change that misleading web page.
2) Let me know so I can remove all SE Linux code from Debian, remove it from
my client's machines, and start work on a competing product.
3) Make formal statements as to limitations of distribution etc, also
clarify to what extent you want SE Linux code removed from the world. Should
I get the upstream maintainer of stat to remove the SE Linux code too? Also
you'll have to get it removed from LSM which is under the GPL, and you had
better hope that the problems with building as a module are fixed quickly -
you can't ship code that links with the kernel unless it's under the GPL.
PS When does the patent expire? If it's due to expire in 1 year or less we
can just wait until it's gone...
--
I do not get viruses because I do not use MS software.
If you use Outlook then please do not put my email address in your
address-book so that WHEN you get a virus it won't use my address in the
>From field.
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
* RE: SELinux Dumb Questions
2002-06-04 23:37 Roland.Jones
@ 2002-06-05 4:26 ` Ed Street
0 siblings, 0 replies; 18+ messages in thread
From: Ed Street @ 2002-06-05 4:26 UTC (permalink / raw)
To: selinux
Hello,
Hey I'm all for any open structure that could meet c2 or better security
guidelines. I believe that selinux comes closer than anything else on
the market. I also believe that if the NSA or any other group wishes to
mangle/modify/add/remove/etc code from other vendors to meet those
guidelines then it's their right (baring copyright infringment and close
source) I also think a lot of people can benefit greatly from this
project and I would really hate to see some greedy company attempt to
snuff the project into their folds.
However after reviewing all the previous emails I have put all my
selinux projects on hold untill I find out where this is going. Just
remember people, if security was illegal only criminals would have
security.
Ed
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 18+ messages in thread
end of thread, other threads:[~2002-06-17 16:44 UTC | newest]
Thread overview: 18+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-05-28 16:11 SE-Linux on SuSE JW
2002-06-03 10:23 ` Carsten Grohmann
2002-06-03 14:50 ` SELinux Dumb Questions Admissions Office
2002-06-03 15:39 ` Russell Coker
2002-06-03 17:50 ` Mirror Offer Admissions Office
2002-06-03 18:45 ` Russell Coker
2002-06-03 19:10 ` Stephen Smalley
2002-06-03 19:16 ` Admissions Office
2002-06-04 21:30 ` SELinux Dumb Questions JW
2002-06-04 21:59 ` Russell Coker
2002-06-05 0:58 ` Dale Amon
[not found] ` <200206042255.g54MtHu1003846@turing-police.cc.vt.edu>
[not found] ` <3CFD49A6.5060400@wirex.com>
2002-06-05 3:52 ` SELinux to GPL or not to GPL Admissions Office
[not found] ` <20020617163139.GF14164@kroah.com>
2002-06-17 16:41 ` To confusing Admissions Office
2002-06-05 1:30 ` SELinux Dumb Questions Admissions Office
-- strict thread matches above, loose matches on Subject: below --
2002-06-03 15:00 Westerman, Mark
2002-06-03 15:34 ` Admissions Office
2002-06-04 23:37 Roland.Jones
2002-06-05 4:26 ` Ed Street
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.