Cc: Andrew Morton <akpm@...>, <casey@...>, <torvalds@...>, <linux-security-module@...>, <linux-kernel@...>, James Morris <jmorris@...>, Paul Moore <paul.moore@...>
> CIPSO is supported on SELinux as well.
That's no reason to extend that design mistake.
If one of the boxes gets broken in all are compromised this way?
Perhaps, but is the result secure? I have severe doubts.
Security that isn't secure is not really useful. You might as well not
bother.
-Andi
-