On Fri, 8 Jun 2007, Greg KH wrote:the way I would describe the difference betwen AA and SELinux is: SELinux is like a default allow IPS system, you have to describe EVERYTHING to the system so that it knows what to allow and what to stop. AA is like a default deny firewall, you describe what you want to happen, and it blocks everything else without you even having to realize that it's there. now I know that this isn't a perfect analyogy, that SELinux doesn't allow something to happen unless it's been told to let it, but in terms of complexity and the amount of work to configure things I think the analogy is close. the fact that the SELinux policy _will_ affect the entire systems means one of two things. 1. you have a policy that exactly describes how every part of the system operates or 2. you have a policy that's exessivly permissive in some parts of the system becouse 'that works' and you either don't understand that part of the system well enough, or don't have time to write a more complete policy. I would argue that with the number of files on a system nowdays (483,000 on my 'minimalistic' gentoo server, 442,000 on my slackware laptop, 800,000 on a ubuntu server at work) it's not possible to do #1, so any deployed policy (especially one done by a disto that needs to work for all it's users) is going to follow #2, frequently to the point where it's not really adding much security. David Lang -
| Arjan van de Ven | [Patch v2] Make PCI extended config space (MMCONFIG) a driver opt-in |
| Tilman Schmidt | git guidance |
| Vu Pham | Re: [Scst-devel] Integration of SCST in the mainstream Linux kernel |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
git: | |
| David Miller | Re: Git and GCC |
| Mike | I don't want the .git directory next to my code. |
| Steffen Prohaska | merge vs rebase: Is visualization in gitk the only problem? |
| David Kastrup | What is the idea for bare repositories? |
| Richard Stallman | Real men don't attack straw men |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| Falk Brockerhoff | ftp-proxy and no route to host issue |
| Pieter Verberne | Remove escape characters from file |
| Chuck Lever | Re: [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Stefan Richter | Re: [GIT]: Networking |
| jamal | Re: [LARTC] ifb and ppp |
