All of lore.kernel.org
 help / color / mirror / Atom feed
* identity
@ 2004-02-23  4:35 Russell Coker
  2004-02-23  6:02 ` identity Joseph Pingenot
                   ` (3 more replies)
  0 siblings, 4 replies; 20+ messages in thread
From: Russell Coker @ 2004-02-23  4:35 UTC (permalink / raw)
  To: SE Linux

One of the benefits of the SE Linux identity is that it tracks the originating 
user through all operations that they perform.

With the user_u identity the utility of the identity for logging user 
activities is reduced.

Some people are talking about ways of tracking the source IP address for a ssh 
connection or other information on the login through user sessions in a 
similar manner.

It seems to me that we would gain a benefit if we had two parts to the 
identity string, the user-name that is compiled into the policy (and checked 
in the constraints file etc), and an arbitary string set by the login program 
or other equally privileged processes to be used for logging.

The idea is to have something like rjc#10.0.0.1:user_r:user_t to indicate that 
I logged in from IP address 10.0.0.1.

Steve, what do you think?

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 20+ messages in thread

end of thread, other threads:[~2004-02-25 19:51 UTC | newest]

Thread overview: 20+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-02-23  4:35 identity Russell Coker
2004-02-23  6:02 ` identity Joseph Pingenot
2004-02-23  6:22   ` identity Russell Coker
2004-02-23 14:47     ` identity Joseph Pingenot
2004-02-23 17:14       ` identity Joshua Brindle
2004-02-24  1:02         ` identity Russell Coker
2004-02-23 13:50 ` identity Stephen Smalley
2004-02-23 23:54   ` identity Russell Coker
     [not found]     ` <200402240308.i1O38Nu6011811@turing-police.cc.vt.edu>
2004-02-24  7:07       ` identity Russell Coker
2004-02-23 14:28 ` identity Stephen Smalley
2004-02-23 19:32   ` identity Joshua Brindle
2004-02-23 19:55     ` identity Stephen Smalley
2004-02-24  0:41   ` identity Russell Coker
2004-02-24 14:47 ` identity James Morris
2004-02-24 14:57   ` identity Stephen Smalley
2004-02-24 20:03     ` [selinux] identity Magosányi Árpád
2004-02-24 20:41       ` Stephen Smalley
2004-02-24 22:45         ` Joshua Brindle
2004-02-25 19:51           ` Rik Faith
2004-02-24 22:50   ` identity Russell Coker

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.