All of lore.kernel.org
 help / color / mirror / Atom feed
* daemons and MCS categories
@ 2006-05-21 23:30 Russell Coker
  2006-05-25  5:07 ` James Morris
  2006-05-29 13:52 ` Christopher J. PeBenito
  0 siblings, 2 replies; 15+ messages in thread
From: Russell Coker @ 2006-05-21 23:30 UTC (permalink / raw)
  To: SE-Linux; +Cc: Shintaro Fujiwara

It seems to me that there is a benefit to giving some categories to daemons.

For example we may have two different categories for files that should be 
protected from each other but which are to be shared by Apache (note that 
categories in MCS are used for protecting integrity as well as 
confidentiality).

One idea that occurred to me is to give Apache (and other daemons) categories 
c128.c255.  Then there are 128 categories that can be used to restrict access 
of files that should not be accessed by daemons and 128 categories that can 
be used for files that can be accessed by daemons.

Another possibility is to have the ability to configure which categories are 
assigned to a daemon via run_init or some similar program.  It would not be 
difficult to read a config file that maps the domain of a daemon to the range 
that should be granted to it.


What do you think?

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2009-05-19  2:52 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-05-21 23:30 daemons and MCS categories Russell Coker
2006-05-25  5:07 ` James Morris
     [not found]   ` <1148538208.1797.23.camel@papa.intrajp-yokosuka.co.jp>
2006-05-25  7:12     ` Russell Coker
2006-05-29 13:52 ` Christopher J. PeBenito
2009-04-20  7:06   ` KaiGai Kohei
2009-04-21  2:05     ` KaiGai Kohei
2009-04-22  8:38       ` KaiGai Kohei
2009-05-11  5:11         ` KaiGai Kohei
2009-05-11 12:37           ` Christopher J. PeBenito
2009-05-12  0:20             ` KaiGai Kohei
2009-05-13  4:07               ` KaiGai Kohei
2009-05-16 16:05           ` Joe Nall
2009-05-18  8:31             ` KaiGai Kohei
2009-05-18 12:57               ` Joe Nall
2009-05-19  2:51                 ` KaiGai Kohei

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.