All of lore.kernel.org
 help / color / mirror / Atom feed
* TE for networked resources
@ 2007-08-16 18:47 shahbaz khan
  2007-08-16 19:06 ` Stephen Smalley
  2007-08-16 20:24 ` Joshua Brindle
  0 siblings, 2 replies; 8+ messages in thread
From: shahbaz khan @ 2007-08-16 18:47 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 612 bytes --]

I was curious while reading Brindle et al paper on enhancing selinux policy
for network domain that do we really need TE for these remote resources.
Can't we just do with IBAC and RBAC? We can let the local subjects handle
the TE with their own types with respect to the IBAC and RBAC of remote
subject. This might be what they call equivalence mechanism. The problems
associated with TE are too tough for selinux and current network controls to
handle. The solutions will cost too much.

Is there any progress on this work. Let me know because I have also working
on this and might be able to assist.

-- 
Shaz

[-- Attachment #2: Type: text/html, Size: 697 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2007-08-16 23:10 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-08-16 18:47 TE for networked resources shahbaz khan
2007-08-16 19:06 ` Stephen Smalley
2007-08-16 21:01   ` shahbaz khan
2007-08-16 21:08     ` Stephen Smalley
2007-08-16 22:53       ` shahbaz khan
2007-08-16 23:10         ` shahbaz khan
2007-08-16 20:24 ` Joshua Brindle
2007-08-16 21:23   ` shahbaz khan

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.