On Fri, Jun 15, 2007 at 05:28:35PM -0400, Karl MacMillan wrote:
Great, but is there the requirement in the CC stuff such that this type
of "delayed re-label" that an AA-like daemon would need to do cause that
model to not be able to be certified like your SELinux implementation
is?
As I'm guessing the default "label" for things like this already work
properly for SELinux, I figure we should be safe, but I don't know those
requirements at all.
thanks,
greg k-h
-