All of lore.kernel.org
 help / color / mirror / Atom feed
* SELinux with IPSec - something going on ?
@ 2003-11-16 15:42 Rusinsky Stanislas Herman W. A.
  2003-11-17 14:37 ` Stephen Smalley
  0 siblings, 1 reply; 32+ messages in thread
From: Rusinsky Stanislas Herman W. A. @ 2003-11-16 15:42 UTC (permalink / raw)
  To: SELinux ML

Hello,

after taking a look at the NSA site I wondered if any work has been made
to integrate IPSec with SELinux.

Is there any draft or specification on what has to be done exactly?

Stanislas.


-- 
One world, One web, One program -- Microsoft ad
Ein volk, Ein Reich, Ein Fuhrer -- Adolf Hitler


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 32+ messages in thread
* Re: SELinux with IPSec - something going on ?
@ 2003-11-17 11:58 Sead Muftic
  0 siblings, 0 replies; 32+ messages in thread
From: Sead Muftic @ 2003-11-17 11:58 UTC (permalink / raw)
  To: rusinskystanislas, SELinux ML

Stanislas:

We (in the Computer Security Institute of GWU) have activated labeling
option of IPSec and used it by SELinux at the receiving end for RBAC.
We also worked out all necessary PT specifications, so we have the first
operational version of network security system based on combination
of IPSec + SELinux.

We are currently making the second round through this development in order
to make it easily installable.

Regards,

Sead Muftic
Research Director
CSPRI/GWU

------------------------------------------------------------------------

>after taking a look at the NSA site I wondered if any work has been made
>to integrate IPSec with SELinux.
>
>Is there any draft or specification on what has to be done exactly?


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 32+ messages in thread
* Re: SELinux with IPSec - something going on ?
@ 2004-10-24  9:30 Park Lee
  2004-10-24 14:53 ` Luke Kenneth Casson Leighton
  2004-10-25 15:51 ` petre rodan
  0 siblings, 2 replies; 32+ messages in thread
From: Park Lee @ 2004-10-24  9:30 UTC (permalink / raw)
  To: sds; +Cc: SELinux, rusinskystanislas

[-- Attachment #1: Type: text/plain, Size: 539 bytes --]

On 2003-11-17 at 14:37 Stephen Smalley wrote:
 
>We have not done any work on integrating SELinux with IPSEC yet;
>at this point, such work would presumably be done based on the new
>Linux 2.6 IPSEC implementation.
 
Now, 11 months have passed, has any work been made to integrate IPSec with SELinux?
I also want to see if there is something I can do with it.
 
Thanks.


--
Best Regards,
Park Lee <parklee_sel@yahoo.com> 
 






		
---------------------------------
Do you Yahoo!?
Yahoo! Mail Address AutoComplete - You start. We finish.

[-- Attachment #2: Type: text/html, Size: 1022 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread
* Re: SELinux with IPSec - something going on ?
@ 2004-10-25 10:10 Stanislas Rusinsky
  2004-10-25 14:59 ` Trent Jaeger
  0 siblings, 1 reply; 32+ messages in thread
From: Stanislas Rusinsky @ 2004-10-25 10:10 UTC (permalink / raw)
  To: Luke Kenneth Casson Leighton; +Cc: SELinux ml, Stephen Smalley, Park Lee

I had to postpone my work so I ain't done much since
last year. At all events it is still on my 'wish
list'.

Stephen: in your mail to Alexis Wagner (subject: '
Re: network object',  12 Aug 2004) you say there was a
debate on implicit labeling vs. explicit labeling, has
ther been any conclusion to it ? 

Luke: The person at IBM was Trent Jaeger.

Stanislas.


	

	
		
Vous manquez d’espace pour stocker vos mails ? 
Yahoo! Mail vous offre GRATUITEMENT 100 Mo !
Créez votre Yahoo! Mail sur http://fr.benefits.yahoo.com/

Le nouveau Yahoo! Messenger est arrivé ! Découvrez toutes les nouveautés pour dialoguer instantanément avec vos amis. A télécharger gratuitement sur http://fr.messenger.yahoo.com

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 32+ messages in thread
* Re: SELinux with IPSec - something going on ?
@ 2004-10-26 15:04 Philip Leo
  2004-10-26 15:23 ` Trent Jaeger
  0 siblings, 1 reply; 32+ messages in thread
From: Philip Leo @ 2004-10-26 15:04 UTC (permalink / raw)
  To: jaegert; +Cc: SELinux, sds, lkcl, rusinskystanislas, parklee_sel

[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1: Type: text/plain; charset=us-ascii, Size: 538 bytes --]

On Mon, 25 Oct 2004 at 10:59, Trent Jaeger wrote:
>Yes, we are working on integration of IPSec with SELinux.  Hope
>to have something for the community soon. 

Could you please tell us what Linux IPsec implementation you are using? Is it FreeS/WAN?
Is Fedora Core itself include an IPsec implementation? or does it use a third-party Linux IPsec implementation?


--
Best regards,
Philip Leo  <phlpleo@yahoo.com> 



				
---------------------------------
Do you Yahoo!?
 Yahoo! Mail – CNET Editors' Choice 2004.  Tell them what you think.

[-- Attachment #2: Type: text/html, Size: 868 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread
* Re: SELinux with IPSec - something going on ?
@ 2004-10-26 17:35 Park Lee
  2004-10-26 18:01 ` Trent Jaeger
  0 siblings, 1 reply; 32+ messages in thread
From: Park Lee @ 2004-10-26 17:35 UTC (permalink / raw)
  To: jaegert; +Cc: SELinux

[-- Attachment #1: Type: text/plain, Size: 303 bytes --]

Hi Trent,
 
As I know that FreeS/WAN is no longer in active development. 
How about transfer to Openswan? Is it feasible?
 
Thanks,
 


--
Best Regards,
Park Lee <parklee_sel@yahoo.com> 
 






		
---------------------------------
Do you Yahoo!?
Yahoo! Mail Address AutoComplete - You start. We finish.

[-- Attachment #2: Type: text/html, Size: 747 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread
* Re: SELinux with IPSec - something going on ?
@ 2004-10-27  5:40 Philip Leo
  0 siblings, 0 replies; 32+ messages in thread
From: Philip Leo @ 2004-10-27  5:40 UTC (permalink / raw)
  To: jaegert; +Cc: SELinux

[-- Attachment #1: Type: text/plain, Size: 584 bytes --]

On Tue, 26 Oct 2004 at 14:01, Trent Jaeger wrote:
 
>As Openswan 2 uses the native IPSec implementation of the Linux
>kernel (although it can use others), my impression is that using 
>Openswan should also be feasible. 

Since there is already a native IPSec implementation in the Linux kernel, can we use it directly? why should we still use other Linux IPsec implementations such as Openswan, FreeS/WAN,etc ?
 
Thanks



--
Best regards,
Philip Leo  <phlpleo@yahoo.com> 



		
---------------------------------
Do you Yahoo!?
Yahoo! Mail Address AutoComplete - You start. We finish.

[-- Attachment #2: Type: text/html, Size: 1010 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread
* Re: SELinux with IPSec - something going on ?
@ 2004-11-05  9:04 Park Lee
  2004-11-05 19:24 ` Trent Jaeger
  0 siblings, 1 reply; 32+ messages in thread
From: Park Lee @ 2004-11-05  9:04 UTC (permalink / raw)
  To: selinux, jaegert

[-- Attachment #1: Type: text/plain, Size: 446 bytes --]

Hi,
 
I also intend to do some work on Integrating IPSEC with network mandatory controls. I'd like to know how many parts this work may include? what these parts respectively are? and what about the workload for doing it?
 
Thanks.


--
Best Regards,
Park Lee <parklee_sel@yahoo.com> 
 






__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 

[-- Attachment #2: Type: text/html, Size: 823 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread
* Re: SELinux with IPSec - something going on ?
@ 2004-11-07 18:33 Park Lee
  2004-11-08 14:55 ` Trent Jaeger
  2004-11-08 15:03 ` Trent Jaeger
  0 siblings, 2 replies; 32+ messages in thread
From: Park Lee @ 2004-11-07 18:33 UTC (permalink / raw)
  To: jaegert; +Cc: jmorris, SELinux

[-- Attachment #1: Type: text/plain, Size: 902 bytes --]

On Tue, 26 Oct 2004 at 11:23, Trent Jaeger wrote:
>Linux 2.6 implements IPSec via a xfrm (pronounced 'transform') 
>subsystem (part of mainline kernel). 
>Basically, you can define 'protocols' that may transform packets upon 
>receipt or prior to send.  IPSec protocols for transform packets using 
>ah and esp are included in the kernel.   
>We hook into the xfrm subsystem and/or use the xfrm data structures 
>to leverage IPSec security associations.
 
I've search 'xfrm' through google, but I wouldn't find much usefull stuff about xfrm. would you please give me some hints on where can I find more information about xfrm ( such as the descriptions of  structures or functions of xfrm, its principles, etc.)
 
Thank you very much.
 


--
Best Regards,
Park Lee <parklee_sel@yahoo.com> 
 






			
---------------------------------
Do you Yahoo!?
 Check out the new Yahoo! Front Page. www.yahoo.com

[-- Attachment #2: Type: text/html, Size: 1396 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread
* Re: SELinux with IPSec - something going on ?
@ 2004-11-11  2:45 Park Lee
  2004-11-11  3:00 ` Trent Jaeger
  0 siblings, 1 reply; 32+ messages in thread
From: Park Lee @ 2004-11-11  2:45 UTC (permalink / raw)
  To: jaegert; +Cc: sds, SELinux

[-- Attachment #1: Type: text/plain, Size: 715 bytes --]

On  Tue, 26 Oct 2004 at 11:23, Trent Jaeger wrote:
> We hook into the xfrm subsystem and/or use the xfrm data 
> structures to leverage IPSec security associations.
 
Then, what items should we add to IPsec security association? Is it still ( source socket security context, destination socket security context, packet security context ) tuple as described in IMPLEMENTING MANDATORY NETWORK SECURITY IN A POLICY-FLEXIBLE SYSTEM (http://www.cs.utah.edu/flux/papers/ajay-thesis-abs.html) .
 
Thank you.


--
Best Regards,
Park Lee <parklee_sel@yahoo.com> 
 






__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 

[-- Attachment #2: Type: text/html, Size: 1165 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread
* Re: SELinux with IPSec - something going on ?
@ 2005-01-12 17:02 Park Lee
  2005-01-12 19:13 ` petre rodan
  0 siblings, 1 reply; 32+ messages in thread
From: Park Lee @ 2005-01-12 17:02 UTC (permalink / raw)
  To: petre rodan; +Cc: SELinux

On 2004-10-25 at 15:51, petre rodan wrote:
> Hi,
> here is a fresh ipsec-tools [1] policy made for 
> gentoo. works flawlessly with my setup [2] (the doc 
> is work in progress).
> 
> [1] http://ipsec-tools.sourceforge.net/
> [2] http://dev.gentoo.org/~kaiowas/doc/wifi_ipsec-
> howto.html
>
> is this usable for any of you?

In racoon.fc, you wrote:

  ... ...
/var/run/pluto\.ctl	-s
system_u:object_r:racoon_var_run_t
  ... ...

But, when we use IPsec-Tools, it seems that there is
no such a file (i.e. /var/run/pluto.ctl). Then, Why
should we write this rule for it?

Thank you.





=====
Best Regards,
Park Lee


		
__________________________________ 
Do you Yahoo!? 
Yahoo! Mail - Helps protect you from nasty viruses. 
http://promotions.yahoo.com/new_mail

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 32+ messages in thread

end of thread, other threads:[~2005-01-12 19:13 UTC | newest]

Thread overview: 32+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-11-16 15:42 SELinux with IPSec - something going on ? Rusinsky Stanislas Herman W. A.
2003-11-17 14:37 ` Stephen Smalley
2003-11-19 10:36   ` Rusinsky Stanislas Herman W. A.
2003-11-19 12:23     ` where to download LSM-patched 2.4 samwun
2003-11-19 13:40       ` Russell Coker
2003-11-20  3:49         ` samwun
2003-11-20  3:55           ` Russell Coker
2003-11-19 19:03       ` Stephen Smalley
  -- strict thread matches above, loose matches on Subject: below --
2003-11-17 11:58 SELinux with IPSec - something going on ? Sead Muftic
2004-10-24  9:30 Park Lee
2004-10-24 14:53 ` Luke Kenneth Casson Leighton
2004-10-25 15:51 ` petre rodan
2004-10-25 15:55   ` Stephen Smalley
2004-10-25 10:10 Stanislas Rusinsky
2004-10-25 14:59 ` Trent Jaeger
2004-10-26 15:04 Philip Leo
2004-10-26 15:23 ` Trent Jaeger
2004-10-26 17:35 Park Lee
2004-10-26 18:01 ` Trent Jaeger
2004-10-28 16:40   ` Park Lee
2004-10-28 16:48     ` Trent Jaeger
2004-10-27  5:40 Philip Leo
2004-11-05  9:04 Park Lee
2004-11-05 19:24 ` Trent Jaeger
2004-11-07 18:33 Park Lee
2004-11-08 14:55 ` Trent Jaeger
2004-11-08 15:03 ` Trent Jaeger
2004-11-11  2:45 Park Lee
2004-11-11  3:00 ` Trent Jaeger
2004-11-11  4:13   ` Park Lee
2005-01-12 17:02 Park Lee
2005-01-12 19:13 ` petre rodan

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.