public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: RazorBlu <razorblu@gmail.com>
To: linux-kernel@vger.kernel.org
Subject: Re: ACLs
Date: Sat, 05 Aug 2006 01:54:48 +0200	[thread overview]
Message-ID: <44D3DE48.8060103@gmail.com> (raw)
In-Reply-To: <F493D385-0915-442A-853A-00B3ED75B8B2@mac.com>

Kyle Moffett wrote:
> You're quite wrong about SELinux; it _is_ part of the kernel.  
> Admittedly it requires a policy to be built and loaded from userspace, 
> but your "ACLs" would require some ACL utilities to apply those from 
> userspace.
That is true, but is it included in every stable release of the kernel 
(by default)? And why aren't more distributions using it (the popular 
ones - for example, I know Mandriva uses grsecurity).
> In any case SELinux is an extremely powerful model; you can define 
> your arbitrary RBAC+TE state machine and constraints, then the kernel 
> applies it to your system; as simple (or horribly complicated, as the 
> case may be) as that.
And what are your feelings on SELinux still being "under research"? Can 
such a system be used in a production environment, when it has not been 
declared a completely mature system by its creators?
> Here's a better security model:  SELinux lets you give root access to 
> everybody and still have a 100% secure system (although it's not 
> really recommended).  Google around for the public SSH-accessible 
> SELinux testbeds with root's password set to "password" or "1234" or 
> whatever and feel free to log in and have a look.  Besides, we do have 
> POSIX ACLs on files; if that's what you're looking for, but that's not 
> extensible enough to cover processes too.
A 100% secure system except for the files that sshd has access to, 
correct? If global access is allowed to root, but it is locked down to 
sshd, then anyone who logs in as root can only modify those files that 
sshd has access to... Or is there a part of the puzzle that I am 
missing? I had not heard of those testbeds before, but I would like to 
see how they are set up.

"Besides, we do have POSIX ACLs on files; if that's what you're looking 
for, but that's not extensible enough to cover processes too." - Precisely.
> Cheers,
> Kyle Moffett
>
Regards,


RazorBlu

  reply	other threads:[~2006-08-04 23:55 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-08-04 21:42 ACLs RazorBlu
     [not found] ` <1154729992.3573.35.camel@brianb>
2006-08-04 22:52   ` ACLs RazorBlu
2006-08-04 23:34     ` ACLs Kyle Moffett
2006-08-04 23:54       ` RazorBlu [this message]
2006-08-05  1:47         ` ACLs Jim Crilly
2006-08-05 19:03           ` ACLs RazorBlu
2006-08-05 20:50             ` ACLs Alistair John Strachan
2006-08-06  0:54             ` ACLs Jim Crilly
2006-08-06  1:23             ` ACLs Alan Cox
2006-08-05 14:07 ` ACLs Alan Cox

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=44D3DE48.8060103@gmail.com \
    --to=razorblu@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox