All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel J Walsh <dwalsh@redhat.com>
To: Karl MacMillan <kmacmillan@tresys.com>
Cc: Stephen Smalley <sds@tycho.nsa.gov>,
	Jeremy Katz <katzj@redhat.com>, James Morris <jmorris@redhat.com>,
	SELinux-dev@tresys.com, SE Linux <selinux@tycho.nsa.gov>,
	Paul Nasrat <pnasrat@redhat.com>,
	James Antill <jantill@redhat.com>
Subject: Re: We are attempting once again to split policy out into	individual RPMS.
Date: Wed, 03 May 2006 11:33:36 -0400	[thread overview]
Message-ID: <4458CD50.9090602@redhat.com> (raw)
In-Reply-To: <1146668892.6723.13.camel@localhost.localdomain>

Karl MacMillan wrote:
> On Tue, 2006-05-02 at 12:26 -0400, Stephen Smalley wrote:
>   
>> On Tue, 2006-05-02 at 11:27 -0400, Jeremy Katz wrote:
>>     
>>> Lots do.  On the order of as many packages as require users at least.
>>> And I'd expect more over time (especially given policy around dbus and
>>> the increasing reliance on dbus through the distribution).  Imagine a
>>> world where every user you wanted to add had to have a separate package
>>> to create the user first. 
>>>       
>> I'm not sure these all require separate policy.  Ideally, we'd like to
>> see greater use of the equivalence class concepts to limit the explosion
>> in policy and not require per-application/per-package policy in so many
>> cases.  There is a tradeoff here in least privilege vs. manageability.
>>
>>     
>
> The other issue that I'm concerned with is how multiple policy types
> will be supported including custom third-part policies. I know that Dan
> has been pushing the concept that policies should be portable across
> base policies, but I think that there is a limit to how far that can go.
> Separate policy packages seem to handle this situation elegantly. So,
> how is the MLS policy going to be handled?
>
> Karl
>
>   
Could we do a requires/provides for this type of thing?

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2006-05-03 15:33 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-05-02 14:24 We are attempting once again to split policy out into individual RPMS Daniel J Walsh
2006-05-02 15:01 ` Joshua Brindle
2006-05-02 15:16   ` Jeremy Katz
2006-05-02 15:33     ` Joshua Brindle
2006-05-02 15:48       ` Jeremy Katz
2006-05-03 15:15         ` Karl MacMillan
2006-05-03 19:02           ` Joshua Brindle
2006-05-03 19:06             ` Jeremy Katz
2006-05-03 19:07             ` Karl MacMillan
2006-05-03 21:14               ` Joshua Brindle
2006-05-04  9:01                 ` Thomas Bleher
2006-05-04 19:18                   ` Thomas Bleher
2006-05-02 15:12 ` Stephen Smalley
2006-05-02 15:27   ` Jeremy Katz
2006-05-02 16:26     ` Stephen Smalley
2006-05-02 16:29       ` Paul Nasrat
2006-05-02 16:53         ` Stephen Smalley
2006-05-02 17:42       ` Stephen Smalley
2006-05-02 17:53         ` Jeremy Katz
2006-05-03 15:08       ` Karl MacMillan
2006-05-03 15:33         ` Daniel J Walsh [this message]
2006-05-03 15:41           ` Karl MacMillan
2006-05-02 15:27   ` Paul Nasrat
2006-05-02 16:13 ` Richard Hally

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4458CD50.9090602@redhat.com \
    --to=dwalsh@redhat.com \
    --cc=SELinux-dev@tresys.com \
    --cc=jantill@redhat.com \
    --cc=jmorris@redhat.com \
    --cc=katzj@redhat.com \
    --cc=kmacmillan@tresys.com \
    --cc=pnasrat@redhat.com \
    --cc=sds@tycho.nsa.gov \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.