Valdis.Kletnieks@vt.edu wrote:That explains so much! "SELinux: you're too dumb to use it, so just keep your hands in your pockets." :-) AppArmor was designed to allow your average sys admin to write a security policy. It makes different design choices than SELinux to achieve that goal. As a result, AppArmor is an utter failure when compared to SELinux's goals, and SELinux in turn is an utter failure when compared to AppArmor's goals. Which is why we have LSM: so we don't have to have this argument here, again. That is a tall order. You can mostly achieve it by not giving the user the root password, but I'm not sure you would like the result :-) Both SELinux and AppArmor can be configured so tightly that you are not going to get to install malware, by preventing the user from installing software. This isn't what users want, so they invariably bypass security and install shiny things if they own the box. SELinux and AppArmor can't help but fail if you put them in that kind of harm's way. Crispin -- Crispin Cowan, Ph.D. http://crispincowan.com/~crispin/ Director of Software Engineering http://novell.com Security: It's not linear - To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
| Vladislav Bolkhovitin | Re: Integration of SCST in the mainstream Linux kernel |
| Linus Torvalds | Re: 2.6.25-git2: BUG: unable to handle kernel paging request at ffffffffffffffff |
| S.Çağlar | Rescheduling interrupts |
| Andi Kleen | Re: [patch] Add basic sanity checks to the syscall execution patch |
git: | |
| Jon Smirl | Re: Figured out how to get Mozilla into git |
| Matt McCutchen | Multiple checkouts of the same repository |
| Willy Tarreau | Multiple working trees with GIT ? |
| Linus Torvalds | Re: git + ssh + key authentication feature-request |
| Richard Stallman | Real men don't attack straw men |
| Adam Getchell | Re: About Xen: maybe a reiterative question but .. |
| Girish Venkatachalam | Thinkpad t61 OpenBSD support? |
| carlopmart | About Xen: maybe a reiterative question but .. |
| Jeff Kirsher | [PATCH 1/3] e1000e: add support for the 82567LM-4 device |
| slavon | Re: e1000_clean_tx_irq: Detected Tx Unit Hang - it's bug? |
| Hugh Dickins | Re: [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
| Eliezer Tamir | Re: [PATCH][BNX2X] added register coments |
