On Tuesday 20 January 2009 3:31:24 pm Jan Engelhardt wrote:
As you noted, the particular problem of resolving the different LSMs
still exists, including the issue of multiplexing per-object state
which is likely to be one of the larger roadblocks to such an approach.
However, in dealing with the issue of personal firewalls I think the
biggest issue will be the user interaction as you described ... how do
you explain to a user who clicked the "allow" button that the system
rejected their traffic?
Unfortunately I don't think this solves the problem, it just changes it
slightly. It is no longer "How do I enable SELinux and XXX personal
firewall?" but instead "How do I enable SELinux's network access
controls and XXX personal firewall?"
--
paul moore
linux @ hp
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html