From: Diyab <diyab@diyab.net>
To: russell@coker.com.au
Cc: SELinux Mail List <selinux@tycho.nsa.gov>
Subject: Re: BSD Secure levels for linux
Date: Thu, 27 Nov 2003 10:45:09 -0500 [thread overview]
Message-ID: <3FC61C05.90400@diyab.net> (raw)
In-Reply-To: <200311271326.53583.russell@coker.com.au>
Russell Coker wrote:
> On Thu, 27 Nov 2003 11:29, Diyab <diyab@diyab.net> wrote:
>
>>Has anyone else run across the kernel patch that implements something
>>similar to the BSD secure levels? Has anyone tried to use this with
>>selinux? I'm also curious what the general thought of the idea is.
>>Good idea? Bad idea? What do you think?
>
>
> The concept of secure levels is to have an option to put the system into a
> mode where module loading and various other things are denied.
>
> You could of course have a SE Linux configuration where you have multiple
> policydb binaries, the one that loads on boot would have the current
> functionality. Other policydb's would have limited functionality (EG prevent
> insmod_t from doing anything other than sending sigchld to init_t and
> preventing load_policy). Then loading a new policy would give a similar
> result to changing a BSD secure level.
I never thought about something like that. On the plus side not only
would you have more control over what your specific "levels" will do but
you can easily and securely switch between levels. The patch I
mentioned does not have that functionality.
>
> If someone else wants to make a start on this then I would be interested in
> merging patches into my policy tree as I think that the functionality is
> useful.
>
I'm going to try this when I get a chance. I do not have time to do it
right away though.
Timothy,
--
I put instant coffee in a microwave and almost went back in time.
-- Steven Wright
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2003-11-27 15:45 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-11-27 0:29 BSD Secure levels for linux Diyab
2003-11-27 2:26 ` Russell Coker
2003-11-27 15:45 ` Diyab [this message]
2003-11-27 20:46 ` Tom
2003-11-27 22:32 ` Russell Coker
2003-11-27 19:45 ` Roberto Nibali
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3FC61C05.90400@diyab.net \
--to=diyab@diyab.net \
--cc=russell@coker.com.au \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.