From: Daniel J Walsh <dwalsh@redhat.com>
To: chanson@TrustedCS.com
Cc: sds@tycho.nsa.gov, rcvalle@linux.vnet.ibm.com, SELinux@tycho.nsa.gov
Subject: Re: SELinux mixed/virtualisation policy
Date: Mon, 11 Apr 2011 17:03:18 -0400 [thread overview]
Message-ID: <4DA36C96.4040800@redhat.com> (raw)
In-Reply-To: <170D6ABBBA770349AA49582A86FCED1503F9EF3A@HAVOC.tcs-sec.com>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On 04/11/2011 04:44 PM, chanson@TrustedCS.com wrote:
>
>
>>> The types could be automatically generated from a template, and
>>> managed by libvirt in much the same way it presently
>> manages categories.
>>>
>>> In any event, he can do the same thing by use of categories rather
>>> than introducing an incomparable set of sensitivities, and that
>>> wouldn't require any changes to the policy toolchain or
>> kernel security server.
>>>
>>
>> Well yes, but currently svirt can support out of the box
>> ~500,000 svirt instances, If we when with a type system,
>> this would probably some problems adding a couple of million
>> types. I don't think we want svirt recompiling and loading
>> policy every time it launches a virtual machine.
>> :^)
>>
>> Reserving a pool of categories at might be the way to go.
>> But at what security level? s15 or s0? Also what about
>> shared data between the virtual machines, read only content.
>> Currently that is just labeled s0.
>>
>
> I would suggest some level in between s0 and s15. I would agree with
> Stephen that dynamic types would be preferred. I guess it just depends
> on the reason you are using the MLS policy.
>
> -Chad
>
>
Because you have virtual machines with data at different levels.
Of course you could have a multi-level virtual machine running with
multiple single level machines on the same multi-level virtual host.
Makes your head ache.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/
iEYEARECAAYFAk2jbJYACgkQrlYvE4MpobPZxACeMoZUpo678s8oPnkcG6BPvtUw
pKIAn37UKb80ghIqFzNyBr+4cxHxvZLD
=cSoU
-----END PGP SIGNATURE-----
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2011-04-11 21:03 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-04-10 17:12 SELinux mixed/virtualisation policy Ramon de Carvalho Valle
2011-04-11 13:40 ` Stephen Smalley
2011-04-11 15:24 ` Daniel J Walsh
2011-04-11 16:33 ` Stephen Smalley
2011-04-11 17:14 ` Ramon de Carvalho Valle
2011-04-11 17:59 ` Daniel J Walsh
2011-04-11 20:44 ` chanson
2011-04-11 21:03 ` Daniel J Walsh [this message]
2011-04-12 12:50 ` Stephen Smalley
2011-04-13 10:24 ` Ramon de Carvalho Valle
2011-04-13 12:19 ` Stephen Smalley
2011-04-13 13:03 ` Ramon de Carvalho Valle
2011-04-13 13:34 ` Russell Coker
2011-04-13 13:51 ` Stephen Smalley
2011-04-13 14:01 ` Daniel J Walsh
2011-04-13 18:33 ` Ramon de Carvalho Valle
2011-04-13 18:32 ` Ramon de Carvalho Valle
2011-04-13 19:09 ` Daniel J Walsh
2011-04-11 14:20 ` Russell Coker
2011-04-11 17:26 ` Ramon de Carvalho Valle
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4DA36C96.4040800@redhat.com \
--to=dwalsh@redhat.com \
--cc=SELinux@tycho.nsa.gov \
--cc=chanson@TrustedCS.com \
--cc=rcvalle@linux.vnet.ibm.com \
--cc=sds@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.