All of lore.kernel.org
 help / color / mirror / Atom feed
From: Thomas Jones <admin@buddhalinux.com>
To: netfilter@lists.netfilter.org
Subject: Re: Request: Submission of Rulesets
Date: Wed, 24 Aug 2005 17:25:06 -0500	[thread overview]
Message-ID: <200508241725.14260.admin@buddhalinux.com> (raw)
In-Reply-To: <200508241607.43943.rob0@gmx.co.uk>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wednesday 24 August 2005 16:07, /dev/rob0 wrote:
> On Wednesday 2005-August-24 13:14, Thomas Jones wrote:
> > Abstract:
>
> I readily admit that this is not a good day for me. I am not operating
> at full capacity, so to speak. But I have to say that this post made no
> sense at all to me. Is it just me? Did anyone else understand it? If
> so, can you explain it?
>
>
> I once saw an online automated generator of scholarly papers. It was
> hilarious! It used language just like this.

Hehehe. Ok...lets make it simple for you. Various security documentation is
composed using a custom XML markup language. Depending on the content,
modules are included or excluded. Given that these document instances are
security in nature they can be secured by a digital signature, encryption, or 
both.

>
> Okay, I think I see a little substance here. The poster wants something
> which lists every possible valid netfilter rule. Right?

Seemingly, you are the the person to do this feat? Realistically, I don't 
expect you or anybody else to have knowledge of all the rules. I have already
developed the basic structure of the DTD. I just want to do some QA on various
rulesets that I have not applied it to.

>
> Unfortunately, the list of valid rules is almost infinite. And what's
> valid may vary in context: what's available in the kernel, other rules
> in the chain, et c. "iptables I OUTPUT -j LOG" is a valid rule (rather
> unfortunate if the local syslogd is logging to a remote syslog server,
> as each packet generates another one ad infinitum), but only valid if
> the LOG target is available.
>

The scenario you describe is what is called a conditional statement. Pretty 
self-explanatory with regards to an XML DTD(or many other disciplines for 
that reason).

>
> It's not even possible.
>

This statement is rather benign. Going back to your conditional statement 
scenario; the DTD is constructed like that of a programming language. It can
be developed by means of pseudo-functions. An element may contain another, so 
on so forth. This is surely within the intended scope and capability.

>
> Perhaps the purpose and intent of the SDI Firewall Rule Subset project
> should be reevaluated.

Because you do no not fully understand does not make it wrong. 


How do you know what I don't know? You are not me.
- ---Zhuang Zi - The Warring States Period


Cheers,
Thomas
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFDDPPHoR5cE1e/kEIRAkM0AJ9KGwqKuzMCJjsm8oQ3RXHK43MVJgCfaqR7
nuf6UbusppcBeD62jfqcmVY=
=qsSS
-----END PGP SIGNATURE-----


  reply	other threads:[~2005-08-24 22:25 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-08-24 18:14 Request: Submission of Rulesets Thomas Jones
2005-08-24 21:07 ` /dev/rob0
2005-08-24 22:25   ` Thomas Jones [this message]
2005-08-24 22:36     ` /dev/rob0
2005-08-24 22:48       ` Thomas Jones
     [not found]         ` <8d48b6ba050824174131a2bbd3@mail.gmail.com>
2005-08-25  0:42           ` Fwd: " Shannon Roddy
  -- strict thread matches above, loose matches on Subject: below --
2005-08-25 11:56 Derick Anderson
2005-08-25 14:35 ` Thomas Jones
2005-08-26 11:57 Derick Anderson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200508241725.14260.admin@buddhalinux.com \
    --to=admin@buddhalinux.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.