All of lore.kernel.org
 help / color / mirror / Atom feed
* Question about integration of IPsec with SELinux?
@ 2005-06-11 10:38 Park Lee
  2005-06-11 17:27 ` Casey Schaufler
  0 siblings, 1 reply; 42+ messages in thread
From: Park Lee @ 2005-06-11 10:38 UTC (permalink / raw)
  To: Stephen Smalley; +Cc: jaegert, SELinux

Dear sir,

    In SELinux Future Work
(http://www.nsa.gov/selinux/info/todo.cfm),
there is an item which says:"Integrate IPSEC with
network mandatory controls".
I know that it means:"integration of SELinux and IPSEC
for the purpose of labeling and protecting network
packets in accordance with security policy".

     But, Would you please tell me :
Is there any motivation of doing it? What is the
significance of doing it? Where to use it? 
and Is there a scene/scenario for it?

     Thank you very much.


Best Regards,
Park Lee

__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 42+ messages in thread
[parent not found: <20050613213951.GB17617@lkcl.net>]
* Re: Question about integration of IPsec with SELinux?
@ 2005-06-14 18:11 Park Lee
  2005-06-14 21:23 ` Casey Schaufler
  0 siblings, 1 reply; 42+ messages in thread
From: Park Lee @ 2005-06-14 18:11 UTC (permalink / raw)
  To: Casey Schaufler; +Cc: Valdis.Kletnieks, Stephen Smalley, Trent Jaeger, SELinux

On Sun, 12 Jun 2005 at 10:46, Casey Schaufler wrote:

> A system compares attributes of processes such
> as user IDs, group memberships, clearances, and
> domain affiliations with attributes of storage
> containers such as ownership, sensitivity, and
> access control lists to determine what accesses
> may be permitted. An interesting special case of
> this behavior is interprocess communication,
> in which the sending process treats the receiving
> process as a storage container. In the local
> system case, where both the sending process and
> the receiving process are on the same machine,
> the attributes relevent to an access decision are
> available, and the IPC mechanism can make the call
> without special accomodation. If the processes
> are on different machines the IPC mechanism must
> provide transport of the required attributes so
> that the decision can be made.


Now let's suppose that processes are on different
machines,
Do you mean that attributes of receiving process
should be sent to the sending machine, which
contains the sending process? and the access control
are made on the sending machine to decide
whether the sending process can do interprocess
communication with its receiving process?
Can we view the sending process as a subject,and view
the receiving process as an object in the interprocess
communication on different machines?

If it is, let's see another situation:
We use the attributes of the sending process to label
the packets which are sent by the sending
process. when the packets are received on receiving
machine, the receiving machine can use the
attributes of the receiving process and the attributes
of the packets to determine whether these packets can
be received. Here, the receiving process becomes
subject, and the packets which represent its sending
process become objects. 
Then, Does this situation become conflict with what
you wrote above?


Thanks a lot.



Best Regards,
Park Lee


		
__________________________________ 
Do you Yahoo!? 
Make Yahoo! your home page 
http://www.yahoo.com/r/hs

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 42+ messages in thread

end of thread, other threads:[~2005-06-16 16:10 UTC | newest]

Thread overview: 42+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-06-11 10:38 Question about integration of IPsec with SELinux? Park Lee
2005-06-11 17:27 ` Casey Schaufler
2005-06-11 18:45   ` Park Lee
2005-06-11 19:18     ` Valdis.Kletnieks
2005-06-11 19:49       ` Casey Schaufler
2005-06-12  2:16         ` Park Lee
2005-06-12 11:44           ` Luke Kenneth Casson Leighton
2005-06-12 12:39             ` Valdis.Kletnieks
2005-06-12 15:20               ` Luke Kenneth Casson Leighton
2005-06-12 19:18                 ` Valdis.Kletnieks
2005-06-12 20:25                   ` Luke Kenneth Casson Leighton
2005-06-12 20:30                     ` Valdis.Kletnieks
2005-06-12 20:52                     ` Luke Kenneth Casson Leighton
2005-06-12 21:45                       ` Valdis.Kletnieks
2005-06-13 13:00                     ` Stephen Smalley
2005-06-13 21:16                       ` Luke Kenneth Casson Leighton
2005-06-14 13:21                         ` Stephen Smalley
2005-06-14 14:31                           ` Trent Jaeger
2005-06-15 22:04                             ` Luke Kenneth Casson Leighton
2005-06-12 23:32                   ` Casey Schaufler
2005-06-13  0:21                     ` Valdis.Kletnieks
2005-06-13 10:01                     ` Luke Kenneth Casson Leighton
2005-06-13 13:37                       ` Valdis.Kletnieks
2005-06-13 14:10                       ` Casey Schaufler
2005-06-13 12:49                 ` Stephen Smalley
2005-06-13 21:17                   ` Luke Kenneth Casson Leighton
2005-06-13 12:37             ` Stephen Smalley
2005-06-13 21:19               ` Luke Kenneth Casson Leighton
2005-06-12 12:34           ` Valdis.Kletnieks
2005-06-12 15:25             ` Luke Kenneth Casson Leighton
2005-06-12 16:16             ` Park Lee
2005-06-12 17:50           ` Casey Schaufler
2005-06-12 16:34   ` Park Lee
2005-06-12 17:02   ` Park Lee
2005-06-12 17:46     ` Casey Schaufler
     [not found] <20050613213951.GB17617@lkcl.net>
2005-06-13 22:03 ` Casey Schaufler
2005-06-13 22:44   ` Luke Kenneth Casson Leighton
2005-06-16 16:01   ` Brian T. Sniffen
  -- strict thread matches above, loose matches on Subject: below --
2005-06-14 18:11 Park Lee
2005-06-14 21:23 ` Casey Schaufler
2005-06-15  1:20   ` Park Lee
2005-06-15  3:00     ` Casey Schaufler

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.