Re: OBSD's perspective on SELinux

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Eduardo Tongson
Date: Saturday, September 22, 2007 - 9:52 am

Hi,

You might be talking about grsecurity and PaX [1]. SELinux hooks
through the LSM [2] framework. LSM was designed to be easily enabled
and disabled, so that should be a fundamental flaw. LSM has valid
criticisms [3] [4].

[1] <http://grsecurity.net>
[2] <http://en.wikipedia.org/wiki/Linux_Security_Modules>
[3] <http://www.grsecurity.net/lsm.php>
[4] <http://www.rsbac.org/documentation/why_rsbac_does_not_use_lsm>

Cheers,
      Ed

On 9/23/07, Darrin Chandler <dwchandler@stilyagin.com> wrote:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 8:34 am)
Re: OBSD's perspective on SELinux, Darrin Chandler, (Sat Sep 22, 9:00 am)
Re: OBSD's perspective on SELinux, Jason Dixon, (Sat Sep 22, 9:20 am)
Re: OBSD's perspective on SELinux, Jeffrey 'jf' Lim, (Sat Sep 22, 9:26 am)
Re: OBSD's perspective on SELinux, Joachim Schipper, (Sat Sep 22, 9:29 am)
Re: OBSD's perspective on SELinux, Ihar Hrachyshka, (Sat Sep 22, 9:45 am)
Re: OBSD's perspective on SELinux, Eduardo Tongson, (Sat Sep 22, 9:52 am)
Re: OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 10:21 am)
Re: OBSD's perspective on SELinux, Ihar Hrachyshka, (Sat Sep 22, 10:38 am)
Re: OBSD's perspective on SELinux, Eduardo Tongson, (Sat Sep 22, 11:00 am)
Re: OBSD's perspective on SELinux, Ted Unangst, (Sat Sep 22, 11:50 am)
Re: OBSD's perspective on SELinux, Stuart Henderson, (Sat Sep 22, 1:00 pm)
Re: OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 1:21 pm)
Re: OBSD's perspective on SELinux, Joachim Schipper, (Sat Sep 22, 1:39 pm)
Re: OBSD's perspective on SELinux, ttw+bsd, (Sat Sep 22, 4:20 pm)
Re: OBSD's perspective on SELinux, L. V. Lammert, (Sat Sep 22, 4:47 pm)
Re: OBSD's perspective on SELinux, Marco Peereboom, (Sat Sep 22, 8:27 pm)
Re: OBSD's perspective on SELinux, Brian Candler, (Sun Sep 23, 12:25 pm)
Re: OBSD's perspective on SELinux, Rui Miguel Silva Seabra, (Sun Sep 23, 2:54 pm)
Re: digitally signed distribution (was: OBSD's perspective ..., Rui Miguel Silva Seabra, (Sun Sep 23, 3:38 pm)
Re: OBSD's perspective on SELinux, David Gwynne, (Mon Sep 24, 7:08 am)
Re: OBSD's perspective on SELinux, Jason Dixon, (Mon Sep 24, 7:25 am)
Re: OBSD's perspective on SELinux, Chris Kuethe, (Mon Sep 24, 7:52 am)
Re: OBSD's perspective on SELinux, Brian Candler, (Mon Sep 24, 8:31 am)
Re: OBSD's perspective on SELinux, Rui Miguel Silva Seabra, (Mon Sep 24, 8:59 am)
Re: OBSD's perspective on SELinux, Ted Unangst, (Mon Sep 24, 10:29 am)
Re: OBSD's perspective on SELinux, Jacob Yocom-Piatt, (Mon Sep 24, 11:17 am)
Re: OBSD's perspective on SELinux, ttw+bsd, (Mon Sep 24, 11:28 am)
Re: OBSD's perspective on SELinux, Ted Unangst, (Mon Sep 24, 12:14 pm)
Re: OBSD's perspective on SELinux, Damien Miller, (Mon Sep 24, 8:09 pm)
Re: OBSD's perspective on SELinux, Marc Espie, (Tue Sep 25, 3:06 am)
Re: OBSD's perspective on SELinux, Marc Espie, (Tue Sep 25, 5:34 am)