All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] What is security_file_type and auth_file_type?
@ 2014-12-21 10:11 Sven Vermeulen
  2014-12-22 14:23 ` Daniel J Walsh
  0 siblings, 1 reply; 4+ messages in thread
From: Sven Vermeulen @ 2014-12-21 10:11 UTC (permalink / raw)
  To: refpolicy

Hi all

Originally, the use of the security_file_type attribute was to reduce the
size of the policy, and its purpose was mainly to differentiate between
files that could be dontaudited and those that couldn't (we want to see when
user domains access security_file_type types that they do not have access
to).

However, I could not find what the scope should be for a security_file_type
(and auth_file_type). When should a type be assigned to be a
security_file_type? "security" is a broad term...

Is it types that could jeopardize the security (confidentiality? integrity?
availability?) of the system when the resources of that type are /read/ by
unauthorized domains? Or is it when the resources are written to? The latter
(writes) is of course much broader (writing to /etc/pam.d or to the libraries
on the system for instance).

Wkr,
	Sven Vermeulen

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2014-12-23 18:13 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-12-21 10:11 [refpolicy] What is security_file_type and auth_file_type? Sven Vermeulen
2014-12-22 14:23 ` Daniel J Walsh
2014-12-23 17:14   ` Sven Vermeulen
2014-12-23 18:13     ` Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.