From: "Eric Peters" <eric@peters.org>
To: "Stephen Smalley" <sds@tislabs.com>
Cc: <SELinux@tycho.nsa.gov>
Subject: Re: SE Linux II?
Date: Wed, 15 Aug 2001 10:39:42 -0700 [thread overview]
Message-ID: <010b01c125b1$45f9c340$020144c0@windows> (raw)
In-Reply-To: Pine.SOL.3.95.1010815130623.5693D-100000@clipper.gw.tislabs.com
That helps alot thanks!
Eric
----- Original Message -----
From: "Stephen Smalley" <sds@tislabs.com>
To: "Eric Peters" <eric@peters.org>
Cc: <SELinux@tycho.nsa.gov>
Sent: Wednesday, August 15, 2001 10:38 AM
Subject: Re: SE Linux II?
>
> On Wed, 15 Aug 2001, Eric Peters wrote:
>
> > however still in a state of question about the representation of a
'domain'.
> > My understanding of a class is just aggregated types (read write/etc)
which
> > could fall under the class 'file', yet what is the definition of a
domain?
>
> The term "class" refers to the kind of object, e.g. a directory, a regular
> file, a device file, a TCP socket, a UDP socket, a message queue, etc.
> For each class, a set of permissions are defined to control the
> services/operations provided for that object.
>
> The terms "domain" and "type" refer to a particular security attribute
> in the security context that is used by the Type Enforcement (TE) policy.
> There have been many papers about TE and its variant DTE. A "domain"
> is simply a security tag for a process, and a "type" is simply a
> security tag for an object. The TE policy configuration specifies
> authorized permissions for various (domain,type,class) triples for
> operations on objects or (domain,domain,class) triples for operations
> between subjects. Abstractly, a domain is a set of processes with
> the same set of permissions to objects (an equivalence class of
> processes). The ability to enter a domain can be limited to specific
> programs by using the entrypoint permission, and the ability to
> transition between domains is controlled. Typically, a TE policy
> directly authorizes users for specific domains. The SELinux
> example security server uses roles as an intermediate abstractions,
> authorizing roles for specific domains and users for specific roles.
>
> --
> Stephen D. Smalley, NAI Labs
> ssmalley@nai.com
>
>
>
>
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2001-08-15 17:39 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2001-08-14 1:57 SE Linux II? Eric Peters
2001-08-14 12:20 ` Stephen Smalley
2001-08-15 1:12 ` Eric Peters
2001-08-15 12:35 ` Stephen Smalley
2001-08-15 16:29 ` Eric Peters
2001-08-15 17:38 ` Stephen Smalley
2001-08-15 17:39 ` Eric Peters [this message]
2001-08-15 17:39 ` Eric Peters
2001-08-15 19:38 ` RBAC/Types Hierarchy Eric Peters
2001-08-15 20:02 ` Stephen Smalley
2001-08-15 20:02 ` Eric Peters
2001-08-15 22:05 ` John Scroggins
2001-08-16 0:14 ` Eric Peters
2001-08-16 1:17 ` John Scroggins
2001-08-15 23:45 ` Dale Amon
[not found] ` <3B7C110C.286A8E4C@earthlink.net>
[not found] ` <20010816071759.C18183@vnl.com>
2001-08-16 19:44 ` John Scroggins
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='010b01c125b1$45f9c340$020144c0@windows' \
--to=eric@peters.org \
--cc=SELinux@tycho.nsa.gov \
--cc=sds@tislabs.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.