From mboxrd@z Thu Jan 1 00:00:00 1970 Message-ID: <3B7C7C69.E7B84C68@earthlink.net> Date: Thu, 16 Aug 2001 19:07:37 -0700 From: John Scroggins MIME-Version: 1.0 To: "SELinux@tycho.nsa.gov" Subject: [Fwd: Partial TOC for Comment] Content-Type: multipart/mixed; boundary="------------8A957F937161E9D5D978401E" Sender: owner-selinux@tycho.nsa.gov List-Id: selinux@tycho.nsa.gov This is a multi-part message in MIME format. --------------8A957F937161E9D5D978401E Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit -------- Original Message -------- X-Mozilla-Status: 8001 X-Mozilla-Status2: 00000000 BCC: dataefx@earthlink.net Message-ID: <3B7C61C3.29886E04@earthlink.net> Date: Thu, 16 Aug 2001 17:13:55 -0700 From: John Scroggins X-Mailer: Mozilla 4.77 [en] (X11; U; Linux 2.4.8-lsm i586) X-Accept-Language: en MIME-Version: 1.0 Subject: Partial TOC for Comment Content-Type: multipart/mixed;boundary="------------F365DA8C7A05EE6BB97147FC" Please give me your feedback/critique on the TOC, and if you can think of additional subject headings (I do have more, but I want to see if this is moving in the right directiom..) TIA, John --------------8A957F937161E9D5D978401E Content-Type: text/html; charset=us-ascii; name="adm082001.html" Content-Transfer-Encoding: 7bit Content-Disposition: inline; filename="adm082001.html" SELinux Administrators Guide Next Previous Contents

SELinux Administrators Guide

John Scroggins dataefx@earthlink.net

Christopher Mahmood ckm@suse.com

August 2001


ABSTRACT


Network security has become a focal point for the IT industry as a whole, based on the increased connectivity required by Government, and private sectors alike. One of the main concerns in system operation is protecting the core operating elements, given the fact that most attacks are intiated with the focus of gaining " root" , or system administrator level privliges. The Linux operating system has been well recieved in a wide range of network duties, its flexibility, and open source modeling is an excellent choice for the development of a " secure" operating system called Security Enhanced Linux (SELinux). SELinux utilizes two separate security methods, Type Enforcement and Role Based Access. This document will assist the reader in determining some of the potential scenarios where the SELinux kernel would become beneficial, thus providing greater security than is available in the standard Linux kernel.

1. Introduction

2. Security Controls

3. SELinux Combined Controls

4. Configuring SELinux


Next Previous Contents --------------8A957F937161E9D5D978401E Content-Type: text/html; charset=us-ascii; name="adm082001-1.html" Content-Transfer-Encoding: 7bit Content-Disposition: inline; filename="adm082001-1.html" SELinux Administrators Guide: Introduction Next Previous Contents

1. Introduction

1.1 Operating System Security

1.2 Enhancing System Security


Next Previous Contents --------------8A957F937161E9D5D978401E Content-Type: text/html; charset=us-ascii; name="adm082001-2.html" Content-Transfer-Encoding: 7bit Content-Disposition: inline; filename="adm082001-2.html" SELinux Administrators Guide: Security Controls Next Previous Contents

2. Security Controls

2.1 Disrectionary Access

2.2 Manadatory Access

2.3 Domain and Type Enforcement

2.4 Role Based Access

2.5 Additional Control Measures


Next Previous Contents --------------8A957F937161E9D5D978401E Content-Type: text/html; charset=us-ascii; name="adm082001-3.html" Content-Transfer-Encoding: 7bit Content-Disposition: inline; filename="adm082001-3.html" SELinux Administrators Guide: SELinux Combined Controls Next Previous Contents

3. SELinux Combined Controls

3.1 Flask Security Architecture

3.2 Linux Security Module (LSM)


Next Previous Contents --------------8A957F937161E9D5D978401E Content-Type: text/html; charset=us-ascii; name="adm082001-4.html" Content-Transfer-Encoding: 7bit Content-Disposition: inline; filename="adm082001-4.html" SELinux Administrators Guide: Configuring SELinux Next Previous Contents

4. Configuring SELinux

4.1 Defining User Roles

4.2 Modifying the Default Type/Context Files


Next Previous Contents --------------8A957F937161E9D5D978401E-- -- You have received this message because you are subscribed to the selinux list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.