Re: SMACK netfilter smacklabel socket match

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Tilman Baumann
Date: Thursday, September 25, 2008 - 12:26 pm

Am 25.09.2008 um 20:26 schrieb Paul Moore:



Sounds like a good idea. When i looked at the SECMARK code i could not  
get my
head around the SELinux specific stuff, so i discarded the idea as to  
complex.

For this to be complete i guess the CIPSO labels for SMACK would need
to be taken into account.
Far more than my quick and dirty approach, and probably more than i'm  
the
right person to do it.
Il try to understand the inner workings of the SECMARK stuff tough.

I will come back to your other comments tomorrow.

Good to know.


I have not investigated further into that, but if there is some way to
match on CIPSO labels, there would be at least a vehicle to base this  
on.

ok


Access control was actually not what i needed in this case.
This would in this case as far as i know actually be done in the SMACK  
LSM.
I'm not sure how much it would make sense to base firewall decisions on
capability checks (i guess this is what you referring to).
Like decisions in the form of who/what may access a process in which  
way.
Please correct me if i understood you wrong.

What i do with this match is just setting some CONNMARK and respectively
FWMARKS to make crazy routing rules for different kinds (marked  
processes)
of my outgoing traffic based on them.


Regards
  Tilman
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
SMACK netfilter smacklabel socket match, Tilman Baumann, (Thu Sep 25, 10:25 am)
Re: SMACK netfilter smacklabel socket match, Paul Moore, (Thu Sep 25, 11:26 am)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Thu Sep 25, 12:26 pm)
Re: SMACK netfilter smacklabel socket match, Paul Moore, (Thu Sep 25, 12:57 pm)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Thu Sep 25, 1:32 pm)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Thu Sep 25, 8:43 pm)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Fri Sep 26, 1:19 am)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Fri Sep 26, 5:35 am)
Re: SMACK netfilter smacklabel socket match, Paul Moore, (Fri Sep 26, 12:55 pm)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Fri Sep 26, 10:01 pm)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Mon Sep 29, 9:21 am)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Mon Sep 29, 8:29 pm)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Wed Oct 1, 4:29 am)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Wed Oct 1, 8:21 am)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Wed Oct 1, 9:55 am)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Wed Oct 1, 11:22 am)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Mon Oct 6, 5:57 am)
Re: SMACK netfilter smacklabel socket match, Ahmed S. Darwish, (Mon Oct 6, 4:05 pm)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Mon Oct 6, 7:42 pm)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Fri Oct 17, 9:57 am)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Fri Oct 17, 10:53 am)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Mon Oct 20, 5:06 am)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Mon Oct 20, 8:01 am)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Tue Oct 21, 8:36 pm)
Re: SMACK netfilter smacklabel socket match, Paul Moore, (Thu Oct 23, 4:55 am)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Thu Oct 30, 9:06 am)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Thu Oct 30, 8:46 pm)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Wed Dec 10, 5:03 pm)
Re: SMACK netfilter smacklabel socket match, Tilman Baumann, (Thu Dec 11, 3:18 am)
Re: SMACK netfilter smacklabel socket match, Casey Schaufler, (Thu Dec 11, 9:29 am)