All of lore.kernel.org
 help / color / mirror / Atom feed
* SeLinux Policy design question
@ 2011-01-26 18:16 Ger Lawlor (gelawlor)
  2011-01-26 20:16 ` Dominick Grift
  2011-01-30 22:20 ` SELinux and Stuxnet Sanjai Narain
  0 siblings, 2 replies; 13+ messages in thread
From: Ger Lawlor (gelawlor) @ 2011-01-26 18:16 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 1094 bytes --]

Hi,

 

I am pondering the best approach to design of appropriate filesystem
labeling that will reduce the long term complexity of managing contexts
and transitions in SeLinux.

If I have a suite of services that interface within a single product and
those services have the potential to share access to similar sub
directory structures, but they 

currently only access files and execute within their own install
directories. It's obviously better to keep locked down any access
outside of each services domain. 

However, what if all services within a product were permitted open
access to all known directories within a product - apart from the
obvious i.e. these services could

Interfere with each other, are there any reasons why this approach would
not be considered a suitable initial approach to seLinux development,
with continued 

Evolution, adding contexts for further refinement of control over time?
Are there best practice guides to filesystem labeling that considers the
complexity that can

Come from excessive labeling?

 

Thanks.

Ger.


[-- Attachment #2: Type: text/html, Size: 3004 bytes --]

^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2011-02-23  3:41 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-01-26 18:16 SeLinux Policy design question Ger Lawlor (gelawlor)
2011-01-26 20:16 ` Dominick Grift
2011-01-26 20:35   ` Ethan Heidrick
2011-01-30 22:20 ` SELinux and Stuxnet Sanjai Narain
2011-01-31  0:39   ` cto
2011-02-22 16:53     ` cto
2011-02-22 17:19       ` Sanjai Narain
2011-02-22 17:43         ` cto
2011-02-22 17:54           ` cto
2011-02-22 21:47             ` Ethan Heidrick
2011-02-22 22:13               ` cto
2011-02-23  2:54                 ` Ethan Heidrick
2011-02-23  3:41                   ` cto

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.