From: Paul Moore <paul.moore@hp.com>
To: Daniel J Walsh <dwalsh@redhat.com>
Cc: James Morris <jmorris@namei.org>, selinux@tycho.nsa.gov
Subject: Re: Speaking of networking...
Date: Wed, 27 Feb 2008 11:13:29 -0500 [thread overview]
Message-ID: <200802271113.29423.paul.moore@hp.com> (raw)
In-Reply-To: <47C5879A.2060108@redhat.com>
On Wednesday 27 February 2008 10:54:02 am Daniel J Walsh wrote:
> Paul Moore wrote:
> > On Wednesday 27 February 2008 9:01:31 am James Morris wrote:
> >> Any further thoughts on how to push the secmark integration
> >> forward?
> >>
> >> The secmark table patch should allow MAC rules to be administered
> >> independently, and I know there has been some demand for the new
> >> (well, now not so new) networking controls.
> >
> > When I asked this question previously the one thing that came up
> > was semanage integration/compatibility. However, there didn't
> > appear to be a consensus as to if that was a good idea because
> > semanage has a rather simplistic view of local network controls due
> > to the limitations of the legacy netif/node controls.
> >
> > I'm with you in that I'd really like to see all of the
> > distributions shift over to using secmark. Beyond the normal
> > performance improvement of moving to secmark, starting with 2.6.25
> > having both secmark and the new network_peer_controls capability
> > enabled should result in a nice performance boost* over the legacy
> > network controls.
> >
> > * No, I don't have any numbers yet, but looking at the code should
> > explain why.
>
> I have no problem with switching to this, as long as we do NO harm.
> IE Everything just works.
> Nothing breaks when the user shuts down iptables.
>
> It needs to be exactly compatible with what we have now.
>
> Permissive mode has got to work.
>
> And it has to be before Beta 1 March 4.
>
> It has to be easy for a user to customize.
>
> Most users will never use it, so it better not be a headache.
I'd like to think that at some point we can evolve the mechanisms/tools
so that normal users can/will take advantage of these controls ... then
again, I'm more than a little bit biased (what do you mean it's hard to
use?!) and a tinge starry-eyed.
Back to the real world, in 2.6.25 _all_ of the "new" networking controls
(including secmark, NetLabel, and labeled IPsec) are dynamic. This
means that by default there are no permission checks applied, not even
unlabeled_t checks; you have to configure something (i.e. load the gun
and point it at your own foot) for the controls to become active. In a
sense, the new additions _should_* actually make life easier for you.
* Really, I mean it this time :)
--
paul moore
linux security @ hp
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2008-02-27 16:56 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-02-27 14:01 Speaking of networking James Morris
2008-02-27 14:51 ` Paul Moore
2008-02-27 15:54 ` Daniel J Walsh
2008-02-27 16:13 ` Paul Moore [this message]
2008-02-27 23:35 ` James Morris
2008-02-27 18:02 ` Stephen Smalley
2008-02-27 22:11 ` James Morris
2008-02-27 23:35 ` Joshua Brindle
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200802271113.29423.paul.moore@hp.com \
--to=paul.moore@hp.com \
--cc=dwalsh@redhat.com \
--cc=jmorris@namei.org \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.