All of lore.kernel.org
 help / color / mirror / Atom feed
* RE: dynamic context transitions - a seteuid parallel
@ 2004-11-01 22:37 Chad Hanson
  2004-11-02  0:43 ` James Morris
                   ` (3 more replies)
  0 siblings, 4 replies; 8+ messages in thread
From: Chad Hanson @ 2004-11-01 22:37 UTC (permalink / raw)
  To: Luke Kenneth Casson Leighton, SE-Linux


Luke Kenneth Casson Leighton wrote:

> okay, so this dynamic context transitions idea is pretty much
> identical to the seteuid equivalence proposals, and doing
> an equivalent of seteuid() it has been made abundantly clear
> [many times], and why, that it should not be done.
> 
> ... question: what it is about MLS that makes it so necessary to
> implement dynamic context transitions?
>

The DoD and associated communities have long requested and utilized the
privilege bracketing technique for information sharing solutions. Thus the
majority of existing applications are built to this framework. TCS and other
ISVs have a large existing code base of fielded accredited solutions based
on this framework.
 
> what are the alternatives?
> 

The alternatives are to overprivilege the application which is not
acceptable or to rewrite all of the applications before they can be used on
this new platform. The latter is goal which can and should be achieved or
time. Applications can streamlined and reorganized to fit into the modular
framework and of cooperating applications. This is a considerable effort and
major roadblock to utilizing SELinux and therefore Linux for these types of
applications.

The other main roadblocks are already being addressed with Linux getting
CAPP EAL3 and soon to be EAL4 certifications. Add LSPP and RBAC and you have
Linux system suitable to address secure information sharing needs.

-Chad

> l.
> 
> p.s. not that i actually understand MLS enough to understand 
> any answers
> [yet] but i'm just encouraging people to bounce ideas.
> 
> 

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 8+ messages in thread
* dynamic context transitions - a seteuid parallel
@ 2004-11-01 19:28 Luke Kenneth Casson Leighton
  0 siblings, 0 replies; 8+ messages in thread
From: Luke Kenneth Casson Leighton @ 2004-11-01 19:28 UTC (permalink / raw)
  To: SE-Linux

okay, so this dynamic context transitions idea is pretty much
identical to the seteuid equivalence proposals, and doing
an equivalent of seteuid() it has been made abundantly clear
[many times], and why, that it should not be done.

... question: what it is about MLS that makes it so necessary to
implement dynamic context transitions?

what are the alternatives?

l.

p.s. not that i actually understand MLS enough to understand any answers
[yet] but i'm just encouraging people to bounce ideas.


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2004-11-03  2:59 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-11-01 22:37 dynamic context transitions - a seteuid parallel Chad Hanson
2004-11-02  0:43 ` James Morris
2004-11-02 16:31   ` Stephen Smalley
2004-11-02  1:12 ` Karl MacMillan
2004-11-02 12:49 ` Frank Mayer
2004-11-03  2:59   ` Russell Coker
2004-11-02 12:58 ` Frank Mayer
  -- strict thread matches above, loose matches on Subject: below --
2004-11-01 19:28 Luke Kenneth Casson Leighton

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.