All of lore.kernel.org
 help / color / mirror / Atom feed
* Re: Crypto FS
@ 2001-02-09 22:04 Pete Loscocco
  2001-02-10  0:29 ` Sandy Harris
  0 siblings, 1 reply; 5+ messages in thread
From: Pete Loscocco @ 2001-02-09 22:04 UTC (permalink / raw)
  To: selinux

Dustin Reyes wrote:

> Will the SE Linux team (NAI Labs, NSA, etc.) be conducting
> an extensive security audit of current Linux disk encryption?
> 

No. The goals of this project are pretty specific. We are looking to
incorporate a flexible mandatory access control architecture into
Linux. We are not trying to find/fix bugs or to analyze security
components like a crypto FS to improve on their designs. That is not to
say that these activities aren't useful or needed to improve the
security of Linux in general. It is just not what we have set out to
do. The security of Linux will be improved by the addition of such
security features as those in SE Linux.

>From the point of view of this project our interest in cryptography is
really to investigate ways that the selection of cryptographic
mechanisms can be integrated with the MAC policy applying the same
principles of policy flexibility and separation of enforcement from the
policy decisions. In short we'd like to see a flexible cryptographic
usage policy which is enforced just as the system security policy is.
We hope to be able to make crypto mechanism selection decisions,
including a decision of whether crypto is even required, based on the
security contexts.

I think that these ideas should be investigated in both file system and
network implementations. Certainly cryptography defined behind a
well-defined crypto API makes this idea more feasible. Doing this for
file cryptography is still something we would like to try in the
future, but have no immediate plans. However, we do have plans to build
upon our previous work in this area for networking. We will be
integrating IKE and IPSEC with the existing MAC policy. As this work
really gets started, we'll have more to say about it.

> I know that the team hopes that the philosophy behind SE Linux's
> architecture and SE Linux itself become a standard in
> the industry, but will the strength of fs crypto be compromised,
> or not examined with the same rigor, as the rest of the
> distribution/system?

Again, the goals of our project are not to improve or certify existing
cryptography. We are interested in providing the necessary system
support to use whatever cryptography the system supports in a way that
can be tied to the mandatory access control policy. The details of the
cryptography should be independent of this support, or as much so as is
possible.

Peter Loscocco
Security-enhanced Linux Project Leader
Information Assurance Research Office
National Security Agency

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 5+ messages in thread
* Crypto FS
@ 2001-02-08 21:53 Dustin Reyes
  2001-02-08 21:56 ` Dustin Reyes
  2001-02-09 13:19 ` Dale Amon
  0 siblings, 2 replies; 5+ messages in thread
From: Dustin Reyes @ 2001-02-08 21:53 UTC (permalink / raw)
  To: selinux

Re: Integrate existing publicly available file cryptography
with file mandatory controls 

Will the SE Linux team (NAI Labs, NSA, etc.) be conducting
an extensive security audit of current Linux disk encryption?

I'm asking this question from more of a legal viewpoint,
due to the Executive branch of the federal government's
traditional negative stance towards *effective* personal data
encryption without key escrow as it interferes with
law enforcement to some degree.

I know that the team hopes that the philosophy behind SE Linux's
architecture and SE Linux itself become a standard in
the industry, but will the strength of fs crypto be compromised,
or not examined with the same rigor, as the rest of the
distribution/system?

It may not be a legal problem per se, but I'm concerned that NSA
culture and tradition would prevent a thorough analysis (and the
release of solutions or enhancements to any problems)...

Finally, I'm not a professional coder or cryptologist, so this question
may be completely invalidated by encrypted filesystems are
already implemented... if so, I apologize in advance.

Thanks for your patience and time.

-Dustin

-- 
Dustin Reyes - crusader@linuxgames.com
LinuxGames - http://www.linuxgames.com

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2001-02-10  0:30 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2001-02-09 22:04 Crypto FS Pete Loscocco
2001-02-10  0:29 ` Sandy Harris
  -- strict thread matches above, loose matches on Subject: below --
2001-02-08 21:53 Dustin Reyes
2001-02-08 21:56 ` Dustin Reyes
2001-02-09 13:19 ` Dale Amon

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.