login
Login
/
Register
Search
Search this site:
Forums
News
Blogs
Features
Site
Home
»
Mailing list archives
»
linux-kernel
»
2007
»
November
»
11
Re: AppArmor Security Goal
view
thread
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
[view in full thread]
From: John Johansen
Subject:
Re: AppArmor Security Goal
Date: Saturday, November 10, 2007 - 8:59 pm
On Sat, Nov 10, 2007 at 05:27:51PM -0800,
david@lang.hm
wrote:
quoted text
> On Sat, 10 Nov 2007, Alan Cox wrote: > >>> but how can the system know if the directory the user wants to add is >>> reasonable or not? what if the user says they want to store their >>> documents in /etc? >> >> A more clear example is wanting to wrap a specific tool with temporary >> rules. Those rules would depend on the exact file being edited at this >> moment - something root cannot know in advance >> (although with apparmor I guess mv $my_file apparmour_magic.name ; foo; >> mv it back might work 8)) > > the mechanism being desired was that the system administrator would setup=
a=20
quoted text
> restrictive policy and a user who wanted a more permissive policy would=
=20
quoted text
> have the ability to make it more permissive. > > this sort of thing is a disaster waiting to happen. >
yep
quoted text
> however, if App Armor sets things up so that there can be a system policy=
=20
quoted text
> that users cannot touch, but users can have a secondary policy that layer=
s=20
quoted text
> over the system one to restrict things further it could be safe. > > if a sysadmin wants to have 'soft' and 'hard' limits of what a user can d=
o,=20
quoted text
> they could put the 'hard' limits in the system policy (and the users=20 > _cannot_ violate these limits), and then set the 'soft' limits in the use=
rs=20
quoted text
> default setup (similar to how .profile is set by default). if a user want=
s=20
quoted text
> to make things less restrictive they could edit or remove the per-user=20 > policy, but would still not be able to violate the system policy. > > however, while this seems attractive, I'm not sure that madness isn't dow=
n=20
quoted text
> the road a little bit. since the users policy would only apply to=20 > themselves, you have the situation that (DAC permissions permitting) the=
=20
quoted text
> files are available to other confined processes becouse they are running =
as=20
quoted text
> other users. this sort of thing will surprise people if the explinations=
=20
quoted text
> aren't done very carefully. >
yes, the devil is in the details.
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
Messages in current thread:
AppArmor Security Goal
, Crispin Cowan
, (Thu Nov 8, 2:33 pm)
Re: AppArmor Security Goal
, Andi Kleen
, (Sat Nov 10, 2:04 pm)
Re: AppArmor Security Goal
, Crispin Cowan
, (Sat Nov 10, 2:24 pm)
Re: AppArmor Security Goal
, david
, (Sat Nov 10, 2:28 pm)
Re: AppArmor Security Goal
, Dr. David Alan Gilbert
, (Sat Nov 10, 3:04 pm)
Re: AppArmor Security Goal
, Crispin Cowan
, (Sat Nov 10, 3:11 pm)
Re: AppArmor Security Goal
, Dr. David Alan Gilbert
, (Sat Nov 10, 3:24 pm)
Re: AppArmor Security Goal
, Crispin Cowan
, (Sat Nov 10, 3:41 pm)
Re: AppArmor Security Goal
, Alan Cox
, (Sat Nov 10, 3:57 pm)
Re: AppArmor Security Goal
, Crispin Cowan
, (Sat Nov 10, 4:14 pm)
Re: AppArmor Security Goal
, Dr. David Alan Gilbert
, (Sat Nov 10, 4:25 pm)
Re: AppArmor Security Goal
, Dr. David Alan Gilbert
, (Sat Nov 10, 4:47 pm)
Re: AppArmor Security Goal
, david
, (Sat Nov 10, 4:52 pm)
Re: AppArmor Security Goal
, Alan Cox
, (Sat Nov 10, 4:54 pm)
Re: AppArmor Security Goal
, Alan Cox
, (Sat Nov 10, 4:56 pm)
Re: AppArmor Security Goal
, david
, (Sat Nov 10, 6:27 pm)
Re: AppArmor Security Goal
, Casey Schaufler
, (Sat Nov 10, 7:17 pm)
Re: AppArmor Security Goal
, John Johansen
, (Sat Nov 10, 8:23 pm)
Re: AppArmor Security Goal
, John Johansen
, (Sat Nov 10, 8:36 pm)
Re: AppArmor Security Goal
, John Johansen
, (Sat Nov 10, 8:55 pm)
Re: AppArmor Security Goal
, John Johansen
, (Sat Nov 10, 8:59 pm)
Re: AppArmor Security Goal
, John Johansen
, (Sat Nov 10, 9:17 pm)
Re: AppArmor Security Goal
, david
, (Sat Nov 10, 9:50 pm)
Re: AppArmor Security Goal
, Rogelio M. Serrano Jr.
, (Sun Nov 11, 12:02 am)
Re: AppArmor Security Goal
, Crispin Cowan
, (Mon Nov 12, 4:50 pm)
Re: AppArmor Security Goal
, Crispin Cowan
, (Mon Nov 12, 4:58 pm)
Re: AppArmor Security Goal
, Joshua Brindle
, (Mon Nov 12, 5:10 pm)
Re: AppArmor Security Goal
, Crispin Cowan
, (Mon Nov 12, 5:13 pm)
Re: AppArmor Security Goal
, John Johansen
, (Mon Nov 12, 6:20 pm)
Re: AppArmor Security Goal
, Casey Schaufler
, (Mon Nov 12, 9:58 pm)
Navigation
Mailing list archives
Recent posts
Popular discussions
linux-kernel
:
Greg Kroah-Hartman
[PATCH 041/196] kobject: add kobject_init_and_add function
Lukas Hejtmanek
Re: Another libata error related to OCZ SSD
Greg Kroah-Hartman
[PATCH 023/196] MCP_UCB1200: Convert from class_device to device
Florian Fainelli
Re: System clock runs too fast after 2.6.27 -> 2.6.28.1 upgrade
Christoph Lameter
[patch 1/4] mmu_notifier: Core code
git
:
Johannes Schindelin
Re: [PATCH 1/2] Add strbuf_initf()
John Bito
[EGIT] Push to GitHub caused corruption
Jakub Narebski
Re: [PATCH 0/2] gitweb: patch view
Junio C Hamano
Re: [PATCH] When a remote is added but not fetched, tell the user.
Andy Parkins
Re: [RFC] Submodules in GIT
git-commits-head
:
Linux Kernel Mailing List
ahci: Workaround HW bug for SB600/700 SATA controller PMP support
Linux Kernel Mailing List
V4L/DVB (11086): au0828: rename macro for currently non-function VBI support
Linux Kernel Mailing List
ceph: client types
Linux Kernel Mailing List
ceph: on-wire types
Linux Kernel Mailing List
crypto: chainiv - Use kcrypto_wq instead of keventd_wq
linux-netdev
:
Andrew Morton
Re: [Bugme-new] [Bug 14969] New: b44: WOL does not work in suspended state
Giuseppe CAVALLARO
Re: [PATCH 03/13] stmmac: add the new Header file for stmmac platform data
Taku Izumi
[PATCH 3/3] ixgbe: add registers etc. printout code just before resetting adapters
Eric Dumazet
rps: some comments
Thomas Gleixner
Re: [RFC PATCH 02/12] On Tue, 23 Sep 2008, David Miller wrote:
openbsd-misc
:
Stephan Andreas
problems with login after xlock in OpenBSD release 4.7
pmc
Make A Change. Alcoholism and Drug Addiction Treatment
ropers
Re: what exactly is enc0?
Fuad NAHDI
Re: What does your environment look like?
Matthew Szudzik
Typo on OpenBSD 4.4 CD Set
Colocation donated by:
Syndicate