From: Tom <tom@lemuria.org>
To: Casey Schaufler <casey@schaufler-ca.com>
Cc: SELinux@tycho.nsa.gov
Subject: Re: Do you trust X server?
Date: Thu, 24 Mar 2005 21:26:17 +0100 [thread overview]
Message-ID: <20050324212616.C13605@lemuria.org> (raw)
In-Reply-To: <20050318162144.32437.qmail@web50202.mail.yahoo.com>; from casey@schaufler-ca.com on Fri, Mar 18, 2005 at 08:21:44AM -0800
On Fri, Mar 18, 2005 at 08:21:44AM -0800, Casey Schaufler wrote:
> Let us be clear. The X consortium has always
> made it plain the the X server provides mechanism,
> not policy.
That it does. Nevertheless, its impact on the policy needs to be
evaluated if you want to use X on an SELinux system. There's no point
in saying "sure, it breaks all my security, but hey, it wasn't designed
to keep the policy intact".
Of course X is policy-ignorant. Most of the programs that SELinux has
policies for are.
> You can trust the X server to the same
> degree you can trust any part of the system that
> does not implement or enforce policy.
i.e. ca. 90% of the applications we've written .te files for so far.
> If you
> chose to use the X server as a component of
> your policy enforcement that is your affair,
> but the appropriate use of that code is your
> responsibility, not that of the X server.
That depends. As far as we can provide policy enforcement externally,
the X server doesn't have to care. However, it has been noted in past
discussions that the X server is, like login or ssh, one of the
programs that cannot fulfill their role within an SELinux environment
without either endangering said environment or becoming policy-aware.
> the "system" is not damaged at all. The DoS
> "attack" is a programming flaw, or "bug" in
> the jargon.
Most security issues are the consequence of from programming flaws. ;)
--
http://web.lemuria.org/pubkey.html
pub 1024D/2D7A04F5 2002-05-16 Tom Vogt <tom@lemuria.org>
Key fingerprint = C731 64D1 4BCF 4C20 48A4 29B2 BF01 9FA1 2D7A 04F5
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2005-03-24 20:26 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-03-18 16:21 Do you trust X server? Casey Schaufler
2005-03-24 20:26 ` Tom [this message]
-- strict thread matches above, loose matches on Subject: below --
2005-03-24 20:41 Casey Schaufler
2005-03-24 21:02 ` Tom
2005-03-17 22:28 Jun OKAJIMA
2005-03-18 5:26 ` Valdis.Kletnieks
2005-03-18 8:35 ` Tom
2005-03-18 16:58 ` Valdis.Kletnieks
2005-03-18 12:38 ` Stephen Smalley
2005-03-18 16:07 ` Daniel J Walsh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20050324212616.C13605@lemuria.org \
--to=tom@lemuria.org \
--cc=SELinux@tycho.nsa.gov \
--cc=casey@schaufler-ca.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.