Re: RFC: Mandatory Access Control for sockets aka "personal firewalls"

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Paul Moore
Date: Tuesday, January 20, 2009 - 1:53 pm

On Tuesday 20 January 2009 3:31:24 pm Jan Engelhardt wrote:

As you noted, the particular problem of resolving the different LSMs 
still exists, including the issue of multiplexing per-object state 
which is likely to be one of the larger roadblocks to such an approach.  
However, in dealing with the issue of personal firewalls I think the 
biggest issue will be the user interaction as you described ... how do 
you explain to a user who clicked the "allow" button that the system 
rejected their traffic?


Unfortunately I don't think this solves the problem, it just changes it 
slightly.  It is no longer "How do I enable SELinux and XXX personal 
firewall?" but instead "How do I enable SELinux's network access 
controls and XXX personal firewall?"

-- 
paul moore
linux @ hp
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: RFC: Mandatory Access Control for sockets aka "persona ..., Paul Moore, (Tue Jan 20, 1:53 pm)