All of lore.kernel.org
 help / color / mirror / Atom feed
* Life cycle process for building products with selinux
@ 2010-05-05 14:22 Alan Rouse
  2010-05-05 15:15 ` Daniel J Walsh
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Alan Rouse @ 2010-05-05 14:22 UTC (permalink / raw)
  To: selinux@tycho.nsa.gov

[-- Attachment #1: Type: text/plain, Size: 1415 bytes --]

I'm not sure where to ask a question like this but I bet someone on the list will know...

Are there any guidelines or "best practices" for building products with selinux?   (Think network appliances for example.)  I have in mind life cycle tasks such as

- Software development:  Where in the software development cycle do you introduce selinux?  Should application developers have to develop on a system confined by selinux?   Is selinux policy maintenance a software development task, or a separate phase in the development cycle?

- System integration:  Is this where selinux is first turned on?

- QA testing:  should QA testing include selinux-specific penetration testing?  Any guidelines or examples of how this is done?  Any tools?

- Who in the development organization needs selinux expertise?

- Are there services that can certify the MAC rules for the operating system?  For the product application?

- Any selinux-specific guidance for customers who install the protected appliance?

- Impact on the process for upgrades and patches because of selinux.  What not to do... for example, turning off selinux to apply a patch.  How to configure a properly confined user for applying patches.

- Organizational policy to complement a properly designed system (separation of duties; physical security; etc).

- War stories, lessons learned... or anything of the sort

Thanks
Alan


[-- Attachment #2: Type: text/html, Size: 2250 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2010-05-06  0:12 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-05-05 14:22 Life cycle process for building products with selinux Alan Rouse
2010-05-05 15:15 ` Daniel J Walsh
2010-05-05 15:47   ` Xavier Toth
2010-05-05 18:25 ` Karl MacMillan
2010-05-06  0:12 ` James Morris

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.