All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] Restricting access to pcscd socket
@ 2014-02-14 19:47 Luis Ressel
  2014-02-14 19:47 ` [refpolicy] [PATCH 1/3] Add a boolean governing mozilla plugin access to pcscd Luis Ressel
                   ` (3 more replies)
  0 siblings, 4 replies; 9+ messages in thread
From: Luis Ressel @ 2014-02-14 19:47 UTC (permalink / raw)
  To: refpolicy

The policy grants the right to access the pcscd socket (PC/SC daemon, a daemon
for accessing smartcards) to some domains which rarely need it: xguest_t,
mozilla_plugin_t and kerberos users (through kerberos_use()). While there are
use cases which require this access, most do not, and access to a smartcard is
something rather critical. Therefore I propose to make this permission a
tunable.

There are some other domains which are granted this access (openct_t,
certmonger_t, certwatch_t, and after my last patch also gpg_agent_t), but they
are specifically crypto-related and should be well-protected, so I decided to
leave their permissions unconditional. (Sure, kerberos is also crypto-related,
but in that policy, the right is granted to any application using kerberos, not
only a separate process.)

What do you think?

Regards,
Luis Ressel

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2014-08-19 13:08 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-02-14 19:47 [refpolicy] Restricting access to pcscd socket Luis Ressel
2014-02-14 19:47 ` [refpolicy] [PATCH 1/3] Add a boolean governing mozilla plugin access to pcscd Luis Ressel
2014-02-14 20:15   ` Sven Vermeulen
2014-02-14 19:47 ` [refpolicy] [PATCH 2/3] Add a boolean governing xguest " Luis Ressel
2014-02-14 19:47 ` [refpolicy] [PATCH 3/3] Add a boolean governing kerberos " Luis Ressel
2014-02-15 20:36 ` [refpolicy] Restricting access to pcscd socket Christopher J. PeBenito
2014-02-15 21:00   ` Luis Ressel
2014-08-11 13:42     ` Luis Ressel
2014-08-19 13:08     ` Christopher J. PeBenito

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.