From: KaiGai Kohei <kaigai@kaigai.gr.jp>
To: SE Linux <selinux@tycho.nsa.gov>
Cc: Toshiharu Harada <haradats@nttdata.co.jp>
Subject: [OT] voice at SecureOS BoF : Japan Linux Conference 2008
Date: Sun, 14 Sep 2008 13:29:16 +0900 [thread overview]
Message-ID: <48CC931C.5000309@kaigai.gr.jp> (raw)
At the last Thursday, we had a BoF session titled as "Let's talk about secure
operating system" with TOMOYO Linux folks (Harada-san) at the Japan Linux
Conference 2008.
About 30-40 audiences were here, and most of them were "geek" of Linux but
not specialists for secure operating system. The purpose of this session is
to collect their opinion or complaint, and to feedback it to the upstreamed
community.
Fortunately, we could have an active discussion, and get well suggestive
opinions. I like to introduce them to share.
* Is SELinux hard to understand now?
- Selectable options are too many, we have to learn many things.
- Existing "rwx" policy is not fine-grained, but so simple
and small number of options enough to remind.
- I want several grade of policy, like "gold policy", "silver policy", ...
- For example, "silver policy" protect Web server only, "gold policy"
protect Web and DNS/DBMS server, and so on.
- Information/documents are legacy and not enough.
- Even if we have enough information/documents, too much things to be
learned will prevent our motivation to utilize SELinux.
- Documentations are written from the viewpoint of SELinux.
It is a long way round to solve a trouble to set up administrators
who tries to set up their application.
- No one mentioned about complexity of raw security policy.
* Now do we have a "killer application"?
- We cannot justify worker-hours to config SELinux without something
attractive bigger than its cost.
- There is no "killer application".
- I had heard similar ones. "It is a secure platform, it is thought as
complex one, it has no killer application". It looks like IPv6.
- In other conference, most of people answered "Yes" for a question of
"I'll move to IPv6, if YouTube is provided only IPv6.".
Thus, something attractive helps people learn and use SELinux.
- Horses need carrots to run. SELinux does not provide us carrot yet.
* Misc topics
- Security is wide concept. Could you make it clear what SELinux can achieve
and cannot?
- Indeed, access controls are a part of security.
- ISO/IEC15408 is a well organized list of security functionalities.
- Naming is bad. "secure os" is confusable.
- "mandatory access control os (Mac OS)" is more confusable. :)
- Are you need secure operating system? I asked at the last.
-> Most of audience agreed.
----
* Moderator's impression
- The default configuration of SELinux got progressed for a few year's.
Not negligible number of audiences answered that I'm using SELinux,
because it is the default configuration.
However, they are hard to find where to be customized, when he tries
to start changing the default configuration.
It might be necessary to limit user's selectable options in same time.
For example, system-config-selinux shows list of all booleans. But it
is too many to choice. Here was an opinion that per-application grouping
and hierarchization of interface can help the situation.
- For documentations, I introduced Justin Mattock's efforts, and should
be translated to Japanese or other languages.
In addition, I thought per-application guidance is necessary,
like "(Samba|Apache|xxxx) set up guide with SELinux".
- A killer application in SELinux is really really really necessary.
Thanks,
--
KaiGai Kohei <kaigai@kaigai.gr.jp>
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
reply other threads:[~2008-09-14 4:29 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=48CC931C.5000309@kaigai.gr.jp \
--to=kaigai@kaigai.gr.jp \
--cc=haradats@nttdata.co.jp \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.