From mboxrd@z Thu Jan 1 00:00:00 1970 From: Venkat Yekkirala Subject: RE: [PATCH 7/7] secid reconciliation-v03: Enforcement for SELinux Date: Fri, 29 Sep 2006 12:17:34 -0400 Message-ID: <36282A1733C57546BE392885C0618592015CF2B9@chaos.tcs.tcs-sec.com> Mime-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Cc: Stephen Smalley , Joshua Brindle , Venkat Yekkirala , netdev@vger.kernel.org, selinux@tycho.nsa.gov, kmacmillan@mentalrootkit.com Return-path: Received: from tcsfw4.tcs-sec.com ([65.127.223.133]:60503 "EHLO tcsfw4.tcs-sec.com") by vger.kernel.org with ESMTP id S1161127AbWI2QRu (ORCPT ); Fri, 29 Sep 2006 12:17:50 -0400 To: James Morris , Paul Moore Sender: netdev-owner@vger.kernel.org List-Id: netdev.vger.kernel.org > > Unless I'm confusing something, there still may be a need > for transitions > > if we want to support both IPsec and NetLabel labeling on the same > > connection. > > I'd prefer not to support this, as it's too complicated, Actually, from my vantage point, it actually seems "natural". > and > CIPSO is a > legacy protocol. Sure. > > Normal IPsec protection applied to CIPSO: yes, but not IPsec > labeling and > CIPSO labeling on the same connection. One use case example can be one SA for Secret in combination with any/all/none of the compartments. And another SA for Top Secret ...