On Friday, August 24 2007 8:58:28 am Kentaro Takeda wrote:
This has been discussed several times on various lists and is not considered
an acceptable solution to blocking incoming stream connection attempts.
Please take a look at the existing LSM stream connection request hooks as
well as how SELinux makes use of them.
Can you explain to me why this is not possible using the existing
security_socket_sock_rcv_skb() LSM hook?
--
paul moore
linux security @ hp
-