login
Header Space

 
 

Re: LSM conversion to static interface

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Crispin Cowan <crispin@...>
Cc: <linux-kernel@...>, LSM ML <linux-security-module@...>, Linus Torvalds <torvalds@...>
Date: Sunday, October 21, 2007 - 10:24 pm

Yes, I think Crispin has succinctly summed it up:  irrevocably closing
the LSM prevents commercial customers from using security modules other
than that provided by their Linux distributor.  As Sarbanes-Oxley and
other regulatory laws require these customers to use "standard
kernels", the result is a rather dreary form of vendor lock-in, where the
security framework is coupled to the distribution.

Though it would require a somewhat undesirable complexity of CONFIG_
flags, it should be possible to construct flexibility enough for everyone
to get what he wants.  For example, it should be possible to configure
kernels with a single security framework hard-linked, AND it should
also be possible to configure kernels such that the default security
framework could be completely replaced at boot time by another, be it
out-of-tree module, or other.

I agree entirely that preserving this form of freedom for the end user
makes Linux a much stronger technology than not.  For one thing, the
consequences of closing LSM are fairly certain to irritate enterprise
commercial customers, which is probably a sign that the technology has
taken a wrong turn.

Tommy F.


Crispin Cowan <crispin@crispincowan.com> wrote:


-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: LSM conversion to static interface, Thomas Fricaccia, (Sun Oct 21, 10:24 pm)
Re: LSM conversion to static interface, Alan Cox, (Mon Oct 22, 6:07 am)
Re: LSM conversion to static interface, Crispin Cowan, (Mon Oct 22, 12:10 pm)
Re: LSM conversion to static interface, Alan Cox, (Mon Oct 22, 12:50 pm)
Re: LSM conversion to static interface, Greg KH, (Mon Oct 22, 12:56 pm)
Re: LSM conversion to static interface, Greg KH, (Sun Oct 21, 11:59 pm)
Re: LSM conversion to static interface, Geert Uytterhoeven, (Tue Oct 23, 12:52 pm)
Re: LSM conversion to static interface, Avi Kivity, (Mon Oct 22, 1:47 pm)
Re: LSM conversion to static interface, Adrian Bunk, (Tue Oct 23, 12:05 pm)
speck-geostationary