From: Pedro Rosa <Pedro.Rosa@ksu.ru>
Cc: Chris <smithchr@mindspring.com>,
securedistros@nl.linux.org, selinux <selinux@tycho.nsa.gov>
Subject: Re: Is this mail list dead?
Date: Wed, 14 Mar 2001 14:35:58 +0300 [thread overview]
Message-ID: <3AAF579E.8070306@ksu.ru> (raw)
In-Reply-To: 3AAE7BC5.50DA0CB@sgi.com
Casey Schaufler wrote:
> Pedro Rosa wrote:
>
>> I would say that securing Linux in a distro structure would be the same
>> as forcing C2 to every Windows install.... Yeah try to use such an
>> install...
>
>
> Every commercial OS today has a C2 option. The lack
> of a C2 version of Linux has been a serious inhibitor
> to adoption in the marketplace. I would guess you're
> refering to the first NT evaluation, which supported
> no networking and no removable media. Building a C2
> (CAPP in Common Criteria jargon) Linux distribution
> is easier than getting corporate marketing types to
> see the value. Say, I bet I know what You do!
>
Well, first you may know that NT does not have C2 implemented from
start. However its implementation is not an easy thing and it enters in
conflict with many third-party programs. Even such things like Internet
Explorer or MS Office cannot live under a C2 environment. However you
may try a good effort to implement a middle solution, depending on your
user's requirements and an evaluation of all security issues that come
from easing the rules of the game.
You are right about the fact that Linux does not have a C2
implementation. However is this thing needed? Frankly I had a moment
where I needed a hard secured NT with C2 enforced to the maximum
possible. Due to stability issues and a few serious security holes in
the system, I had to drop out the project. Later, I took Linux for a
try in the same task. By taking the same requirements, I managed to
produce a box quite near to the one I tried with NT. I should say I
didn't follow C2 in this case, I just went for what was required to be
secured and created a solution to manage it. Interesting to note that
for nearly 1,5 year there was no break in. This is not fully a virtue
of the security implemented in the system (well the thing is quite
weaker than C2) but it does not allow a break in in the first try.
The lack of C2 on Linux sounds like a serious drawback. But how many
commercial organisations do implement this thing? I wonder that even
those who do really need it, barely realise that they have to seriously
configure Windows for such task...
Anyway, I would defend the existence of C2. And I do think that things
similar to C2 should be implemented on Linux (yes, it will be very hard
to do this). But not as to give Linux a slogan "It's C2 certified!" but
to answer particular requirements of users that do really need such
stuff. Not everyone needs such certifications. and note that their
implementation carries costs. Costs may be on performance (very high
ones), flexibility and even stability. This last one may even turn a C2
implementation into 0 as it was my case... A few system files broke
after a crash, and the whole thing was completly accessible to anyone
who just pressed "Enter" in the login.
Ektanoor
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2001-03-14 11:48 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <Pine.LNX.4.32.0103121443130.16938-100000@arwin.microunity.com>
[not found] ` <3AAD5908.73A44E4C@wirex.com>
2001-03-12 23:40 ` Is this mail list dead? Tracy R Reed
2001-03-13 4:29 ` Chris
2001-03-13 12:02 ` Pedro Rosa
2001-03-13 19:57 ` Casey Schaufler
2001-03-14 11:35 ` Pedro Rosa [this message]
[not found] ` <3AAEB0F5.57BBA301@gmx.de>
[not found] ` <20010313161336.E4500@ultraviolet.org>
2001-03-14 22:38 ` securedistros mailing list subscription info [was: Re: Is this mail list dead?] Martin Stricker
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3AAF579E.8070306@ksu.ru \
--to=pedro.rosa@ksu.ru \
--cc=securedistros@nl.linux.org \
--cc=selinux@tycho.nsa.gov \
--cc=smithchr@mindspring.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.