All of lore.kernel.org
 help / color / mirror / Atom feed
* Policy infrastructure problems and improvement
@ 2009-04-09 15:28 James Carter
  2009-04-10  4:19 ` Casey Schaufler
                   ` (2 more replies)
  0 siblings, 3 replies; 15+ messages in thread
From: James Carter @ 2009-04-09 15:28 UTC (permalink / raw)
  To: SELinux

I am looking at improving the policy infrastructure.  The ultimate goal
is to make SELinux policy writing, policy customization, policy
management, and administration easier and less confusing. My focus will
be on the userspace parts of SELinux. 

My plan to do this is as follows:
(1) Determine and enumerate the existing problems of the current
infrastructure.
(2) Determine the desired capabilities and architecture of the ideal
infrastructure.
(3) Determine the changes needed to the current architecture to fix the
current problems and to provide the desired capabilities.
(4) Make the policy infrastructure as close to the ideal as possible
while providing some kind of backwards compatibility and taking other
practicalities into consideration.

I have had some informal discussions with others internally and at
Tresys, and the five emails to follow have my summary of the problems
that have been identified in those discussions.

My hope is that there will be a good discussion and that others on the
list will identify other problems and provide more details or examples
to the problems already identified.

-- 
James Carter <jwcart2@tycho.nsa.gov>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2009-04-14 13:31 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-04-09 15:28 Policy infrastructure problems and improvement James Carter
2009-04-10  4:19 ` Casey Schaufler
2009-04-10 12:34   ` James Carter
2009-04-10 14:51     ` Joe Nall
2009-04-10 16:33       ` James Carter
2009-04-10 17:44         ` Joe Nall
2009-04-13  7:28       ` Alexey S.
2009-04-13 11:31         ` Daniel J Walsh
2009-04-11  2:45     ` Casey Schaufler
2009-04-14 13:31       ` James Carter
2009-04-10 12:43 ` Alexey S
2009-04-10 12:45   ` Stephen Smalley
2009-04-10 14:28     ` Joe Nall
2009-04-13  7:10     ` Alexey S
2009-04-10 13:09 ` Xavier Toth

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.