From: aranea@aixah.de (Luis Ressel)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] Restricting access to pcscd socket
Date: Sat, 15 Feb 2014 22:00:25 +0100 [thread overview]
Message-ID: <20140215220025.2cb38402@gentp.lnet> (raw)
In-Reply-To: <52FFCFC0.8030407@tresys.com>
On Sat, 15 Feb 2014 15:36:16 -0500
"Christopher J. PeBenito" <cpebenito@tresys.com> wrote:
> Typically I would take something like this. Conditionally making the
> policy stricter is usually a good thing. I'm not so sure that it
> makes sense here. It doesn't seem like it buys much.
>
I'm not sure about either. If I understand it correctly, once one
application accesses a smartcard, it gets exclusive access - other
applications can't access it anymore until the using application stops
using the smartcard (and hopefully resets it before).
On the other hand, something as security-critical as a smartcard daemon
should be well-protected, and mozilla_plugin_t is a really exposed
domain. Same goes for xguest_t - you expect that one to have minimal
permissions, and that normally wouldn't include access to smartcards.
Therefore, I think it would be a good idea to add these booleans. Could
you perhaps elaborate a bit on them "not buying much"?
Regards,
Luis Ressel
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 966 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20140215/439d0445/attachment.bin
next prev parent reply other threads:[~2014-02-15 21:00 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-02-14 19:47 [refpolicy] Restricting access to pcscd socket Luis Ressel
2014-02-14 19:47 ` [refpolicy] [PATCH 1/3] Add a boolean governing mozilla plugin access to pcscd Luis Ressel
2014-02-14 20:15 ` Sven Vermeulen
2014-02-14 19:47 ` [refpolicy] [PATCH 2/3] Add a boolean governing xguest " Luis Ressel
2014-02-14 19:47 ` [refpolicy] [PATCH 3/3] Add a boolean governing kerberos " Luis Ressel
2014-02-15 20:36 ` [refpolicy] Restricting access to pcscd socket Christopher J. PeBenito
2014-02-15 21:00 ` Luis Ressel [this message]
2014-08-11 13:42 ` Luis Ressel
2014-08-19 13:08 ` Christopher J. PeBenito
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140215220025.2cb38402@gentp.lnet \
--to=aranea@aixah.de \
--cc=refpolicy@oss.tresys.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.