All of lore.kernel.org
 help / color / mirror / Atom feed
* PMS and SELinux
@ 2007-07-30 19:25 shahbaz khan
  2007-07-31 20:49 ` Joshua Brindle
  0 siblings, 1 reply; 4+ messages in thread
From: shahbaz khan @ 2007-07-30 19:25 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 1350 bytes --]

I would like to ask a few questions from the experts regarding some
implementations. I am working on a survey on selinux rsbac and grsecurity.
Got some from mailing lists but need more. References will be appreciated..
They are the following:


   1. What is a security aware application. What functionality it can
   provide? Has this functionality been provide in the other competitors.
   2. Where are sids implemented. I have heard that they are history now.
   How are they opaque to object managers?
   3. What difference has PMS brought to selinux. Do we have such in
   other implementations?
   4. How is PMS implemented? Any technical documents? Is it a secure
   application using the extended api?
   5. How and where is AVC implemented?
   6. Is there any good logging facility apart from regular denial? I
   have heard rsbac and grsecurity has better logging facilities.
   7. SELinux uses syscall interception. Is it through LSM? How does
   rsbac and grsecurity manage this?
   8. Of the topic but how does grsecurity implement acls and rbac. Is
   rbac used through the acls or a seperate module?
   9. How can we best judge the network controls of rsbac and grsecurity
   w.r.t. implementation, usability and functionality?

I will be glad to put the names of responders in my survey document's
acknowledgements.

Thank you.
Shaz.

[-- Attachment #2: Type: text/html, Size: 1449 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread
* PMS and selinux
@ 2007-07-30 19:48 shahbaz khan
  0 siblings, 0 replies; 4+ messages in thread
From: shahbaz khan @ 2007-07-30 19:48 UTC (permalink / raw)
  To: selinux

I had some problems sending this so sorry for twin sends if ahappened so.

I would like to ask a few questions from the experts regarding some
implementations. I am working on a survey on selinux rsbac and
grsecurity. Got some from mailing lists but need more. References will
be appreciated.. They are the following:

1. What is a security aware application. What functionality it can
provide? Has this functionality been provide in the other competitors.

2. Where are sids implemented. I have heard that they are history now.
How are they opaque to object managers?

3. What difference has PMS brought to selinux. Do we have such in
other implementations?

4. How is PMS implemented? Any technical documents? Is it a secure
application using the extended api?

5. How and where is AVC implemented?

6.Is there any good logging facility apart from regular denial? I have
heard rsbac and grsecurity has better logging facilities.

7. SELinux uses syscall interception. Is it through LSM? How does
rsbac and grsecurity manage this?

8. Of the topic but how does grsecurity implement acls and rbac. Is
rbac used through the acls or a seperate module?

9. How can we best judge the network controls of rsbac and grsecurity
w.r.t. implementation, usability and functionality?

I will be glad to put the names of responders in my survey document's
acknowledgements.

Thank you.
Shaz.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2007-07-31 21:40 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-07-30 19:25 PMS and SELinux shahbaz khan
2007-07-31 20:49 ` Joshua Brindle
2007-07-31 21:40   ` shahbaz khan
  -- strict thread matches above, loose matches on Subject: below --
2007-07-30 19:48 PMS and selinux shahbaz khan

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.