From: Mimi Zohar <zohar@linux.vnet.ibm.com>
To: Chuck Lever <chuck.lever@oracle.com>, linux-integrity@vger.kernel.org
Cc: "Serge E. Hallyn" <serge@hallyn.com>,
Michael Halcrow <mhalcrow@google.com>
Subject: Re: Fwd: New Version Notification for draft-cel-nfsv4-linux-seclabel-xtensions-00.txt
Date: Tue, 10 Apr 2018 19:10:00 -0400 [thread overview]
Message-ID: <1523401800.5268.61.camel@linux.vnet.ibm.com> (raw)
In-Reply-To: <FB6125E9-528C-47DD-9774-86D9D4975A54@oracle.com>
Hi Chuck,
On Tue, 2018-04-10 at 08:44 -0600, Chuck Lever wrote:
> > Begin forwarded message:
> >
> > From: internet-drafts@ietf.org
> > Subject: New Version Notification for draft-cel-nfsv4-linux-seclabel-xtensions-00.txt
> > Date: April 10, 2018 at 8:36:36 AM MDT
> > To: "Charles Lever" <chuck.lever@oracle.com>, "Chuck Lever" <chuck.lever@oracle.com>
> >
> >
> > A new version of I-D, draft-cel-nfsv4-linux-seclabel-xtensions-00.txt
> > has been successfully submitted by Charles Lever and posted to the
> > IETF repository.
> >
> > Name: draft-cel-nfsv4-linux-seclabel-xtensions
> > Revision: 00
> > Title: Linux-related Extensions to NFS version 4.2 Security Labels
> > Document date: 2018-04-09
> > Group: Individual Submission
> > Pages: 8
> > URL: https://www.ietf.org/internet-drafts/draft-cel-nfsv4-linux-seclabel-xtensions-00.txt
> > Status: https://datatracker.ietf.org/doc/draft-cel-nfsv4-linux-seclabel-xtensions/
> > Htmlized: https://tools.ietf.org/html/draft-cel-nfsv4-linux-seclabel-xtensions-00
> > Htmlized: https://datatracker.ietf.org/doc/html/draft-cel-nfsv4-linux-seclabel-xtensions
> >
> >
> > Abstract:
> > NFS version 4.2 introduces an optional feature known as NFSv4
> > Security Labels. This document extends NFSv4 Security Labels to
> > support Linux file capabilities and the Linux Integrity Measurement
> > Architecture.
> >
Very nice! Thank you so much for writing this up.
> >
> >
> > Please note that it may take a couple of minutes from the time of submission
> > until the htmlized version and diff are available at tools.ietf.org.
> >
> > The IETF Secretariat
>
> Initial revision, by no means final. Review comments welcome.
>
> I'm toying with some ideas here. If you find anything controversial
> you are welcome to provide input.
"security.ima" may contain either a file hash or a file signature.
"security.evm" may contain either an HMAC or a signature of the file
metdata. Only the security.evm portable and immutable file signature,
not the HMAC which is TPM specific, will be applicable.
The last paragraph of section 1.1 mentions that the private key needs
to be protected, which is fine, but then mentions a TPM. This might
be a bit confusing in the context of EVM/IMA-appraisal as only the
trusted "master" key, which is used to encrypt/decrypt the EVM key, is
created and decrypted by the TPM.
Mimi
next prev parent reply other threads:[~2018-04-10 23:10 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <152337099624.13448.11040477333954216664.idtracker@ietfa.amsl.com>
2018-04-10 14:44 ` Fwd: New Version Notification for draft-cel-nfsv4-linux-seclabel-xtensions-00.txt Chuck Lever
2018-04-10 23:10 ` Mimi Zohar [this message]
2018-04-19 16:32 ` Serge E. Hallyn
[not found] ` <1524589082.3364.26.camel@linux.vnet.ibm.com>
2018-04-24 18:07 ` [Fwd: Re: Fwd: New Version Notification for draft-cel-nfsv4-linux-seclabel-xtensions-00.txt] Chuck Lever
2018-04-24 19:47 ` Serge E. Hallyn
2018-04-24 21:10 ` Chuck Lever
2018-06-07 13:45 ` Serge E. Hallyn
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1523401800.5268.61.camel@linux.vnet.ibm.com \
--to=zohar@linux.vnet.ibm.com \
--cc=chuck.lever@oracle.com \
--cc=linux-integrity@vger.kernel.org \
--cc=mhalcrow@google.com \
--cc=serge@hallyn.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).