From: guido@trentalancia.com (Guido Trentalancia)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] Question: and the policy grows...
Date: Thu, 17 Mar 2011 22:08:44 +0100 [thread overview]
Message-ID: <1300396124.31755.48.camel@tesla.lan> (raw)
In-Reply-To: <20110317202433.GA6695@siphos.be>
Hi Sven !
On Thu, 17/03/2011 at 21.24 +0100, Sven Vermeulen wrote:
> On Thu, Mar 17, 2011 at 08:40:04PM +0100, Guido Trentalancia wrote:
> > There is at least the limit of not having many people on this list
> > compared to most other Linux projects. Perhaps security is considered
> > something boring to the average user/developer. Or even more likely
> > SELinux is still perceived as "difficult to get into" (a documentation
> > issue).
>
> I think it is more that security is still seen as an expert field, and most
> organizations don't have the people or resources to invest in expert fields
> beyond using what their vendor is offering. And the investments they do is
> more targetting immediate threats like centralized user management, proper
> auditing and such. Mandatory Access Control, although offered on all
> enterprise-grade platforms, is often disregarded as too difficult to master.
I would say most people see security as a very optional, very boring
thing.
It couldn't be otherwise, because (hardening) guidelines such as those
from NSA (for Linux or other OS such Windows) require absolutely no
knowledge about the OS. On Windows, it is really a matter of launching
regedit and a couple of other Microsoft applications and just following
the recommended configuration. On Linux it's just a bit more (editing a
few configuration files maybe). Still many (if not most) people do not
care about investing those 30 minutes...
It's a situation very similar to preventive medicine ("it will never
happen to me").
But I would stop here because perhaps we are getting a bit off-topic
now.
> It is a good thing that RedHat and other (commercial) distributions are
> (starting to) offer SELinux-enabled systems by default. By integrating it
> immediately (and not offering it as an "additional" option) they somewhat
> force organizations to at least understand what it does or is supposed to
> do. By having the non-commercial distributions focus on SELinux more and
> more, this will also create awareness in the community.
Sure.
> Having a working reference policy to start from is an important part here,
> because most community distributions don't have the resources to build off
> general policies that work for the majority of users themselves. I am
> perfectly aware that the reference policy does not entirely do what I would
> expect a policy to do on *my* system, but for a distribution, it is a
> perfect starting point.
Yes.
> The next step then - once a distribution has at least one policy that is
> working well - is to offer the necessary documentation and help for
> administrators to create and manage their own policies [1]. After all, if a
> distribution only delivers the policy but offers little help to modify or
> install your own, then the distributions' the security administrator and not
> some team in the organization.
I think I got lost in the last sentence. But the documentation you
describe is generic documentation about policy writing. So it's
something that could be written once for everybody (ideally a joint
effort).
My question was more about methods for policy reduction and tightening
(a policy management issue)... Can you think about solutions to that
problem ?
Regards,
Guido
next prev parent reply other threads:[~2011-03-17 21:08 UTC|newest]
Thread overview: 46+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-03-17 13:50 [refpolicy] Question: and the policy grows Guido Trentalancia
2011-03-17 14:25 ` Daniel J Walsh
2011-03-17 16:04 ` Guido Trentalancia
2011-03-17 16:44 ` Daniel J Walsh
2011-03-17 17:54 ` Christopher J. PeBenito
2011-03-17 18:34 ` Daniel J Walsh
2011-03-17 19:49 ` Daniel J Walsh
2011-03-18 13:30 ` Christopher J. PeBenito
2011-03-17 20:15 ` Guido Trentalancia
2011-03-18 13:35 ` Christopher J. PeBenito
2011-03-18 15:25 ` Guido Trentalancia
2011-03-17 19:40 ` Guido Trentalancia
2011-03-17 19:55 ` Daniel J Walsh
2011-03-17 20:27 ` Guido Trentalancia
2011-03-18 13:38 ` Christopher J. PeBenito
2011-03-17 20:24 ` Sven Vermeulen
2011-03-17 21:08 ` Guido Trentalancia [this message]
2011-03-17 21:34 ` Sven Vermeulen
2011-03-17 23:04 ` Guido Trentalancia
2011-03-18 13:52 ` Christopher J. PeBenito
2011-03-18 15:20 ` Guido Trentalancia
2011-03-17 23:08 ` Mark Montague
2011-03-18 6:06 ` Sven Vermeulen
2011-03-18 10:19 ` Dominick Grift
2011-03-18 12:31 ` Guido Trentalancia
2011-03-17 22:56 ` Mark Montague
2011-03-18 10:12 ` Dominick Grift
2011-03-18 13:37 ` Stephen Smalley
2011-03-18 15:37 ` Dominick Grift
2011-03-17 23:24 ` SE Linux use - was: " Russell Coker
2011-03-18 0:33 ` Guido Trentalancia
2011-03-18 2:11 ` Jason Axelson
2011-03-18 13:23 ` James Carter
2011-03-18 14:33 ` Russell Coker
2011-03-18 14:57 ` Christopher J. PeBenito
2011-03-18 15:48 ` Guido Trentalancia
2011-03-18 23:40 ` Russell Coker
2011-03-18 15:45 ` Guido Trentalancia
2011-03-18 23:52 ` Russell Coker
2011-03-19 14:37 ` Guido Trentalancia
2011-03-18 14:08 ` Christopher J. PeBenito
2011-03-18 13:45 ` [refpolicy] " Christopher J. PeBenito
2011-03-18 15:09 ` Guido Trentalancia
2011-03-18 17:14 ` [refpolicy] dual mailing list (was Question: and the policy grows...) Guido Trentalancia
2011-03-18 18:40 ` Daniel J Walsh
2011-03-18 19:13 ` Guido Trentalancia
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1300396124.31755.48.camel@tesla.lan \
--to=guido@trentalancia.com \
--cc=refpolicy@oss.tresys.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.