Re: OBSD's perspective on SELinux

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Rui Miguel Silva Seabra
Date: Sunday, September 23, 2007 - 2:54 pm

On Sat, Sep 22, 2007 at 06:47:46PM -0500, L. V. Lammert wrote:

Can you say "root can only run this and that application when su'ed from
that guy, and may not open any net connection, but open this file and none
else" in OpenBSD? If so, how can I do it? :)


A couple of years is a long time, in terms of software, so I'd expect such
instabilities, if SELinux is the culprit, to be fixed.

But I won't deny it's learning curve is extremely steep. So steep indeed
that most of the time it's easier to have carefully laid out standard
unix permissions associated with sudo and specific users for specific
software.

The *need* for things like SELinux exists in some niche markets where
higher levels of security are necessary.

Remember: OpenBSD still doesn't have a digitally signed code distribution,
and in some places that means it can't enter! Stupid, I know, but not too
stupid for the "blame game" rules, which sort of ignore the "secure by
design" initiatives.

Rui

-- 
All Hail Discordia!
Today is Sweetmorn, the 47th day of Bureaucracy in the YOLD 3173
+ No matter how much you do, you never do enough -- unknown
+ Whatever you do will be insignificant,
| but it is very important that you do it -- Gandhi
+ So let's do it...?
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 8:34 am)
Re: OBSD's perspective on SELinux, Darrin Chandler, (Sat Sep 22, 9:00 am)
Re: OBSD's perspective on SELinux, Jason Dixon, (Sat Sep 22, 9:20 am)
Re: OBSD's perspective on SELinux, Jeffrey 'jf' Lim, (Sat Sep 22, 9:26 am)
Re: OBSD's perspective on SELinux, Joachim Schipper, (Sat Sep 22, 9:29 am)
Re: OBSD's perspective on SELinux, Ihar Hrachyshka, (Sat Sep 22, 9:45 am)
Re: OBSD's perspective on SELinux, Eduardo Tongson, (Sat Sep 22, 9:52 am)
Re: OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 10:21 am)
Re: OBSD's perspective on SELinux, Ihar Hrachyshka, (Sat Sep 22, 10:38 am)
Re: OBSD's perspective on SELinux, Eduardo Tongson, (Sat Sep 22, 11:00 am)
Re: OBSD's perspective on SELinux, Ted Unangst, (Sat Sep 22, 11:50 am)
Re: OBSD's perspective on SELinux, Stuart Henderson, (Sat Sep 22, 1:00 pm)
Re: OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 1:21 pm)
Re: OBSD's perspective on SELinux, Joachim Schipper, (Sat Sep 22, 1:39 pm)
Re: OBSD's perspective on SELinux, ttw+bsd, (Sat Sep 22, 4:20 pm)
Re: OBSD's perspective on SELinux, L. V. Lammert, (Sat Sep 22, 4:47 pm)
Re: OBSD's perspective on SELinux, Marco Peereboom, (Sat Sep 22, 8:27 pm)
Re: OBSD's perspective on SELinux, Brian Candler, (Sun Sep 23, 12:25 pm)
Re: OBSD's perspective on SELinux, Rui Miguel Silva Seabra, (Sun Sep 23, 2:54 pm)
Re: digitally signed distribution (was: OBSD's perspective ..., Rui Miguel Silva Seabra, (Sun Sep 23, 3:38 pm)
Re: OBSD's perspective on SELinux, David Gwynne, (Mon Sep 24, 7:08 am)
Re: OBSD's perspective on SELinux, Jason Dixon, (Mon Sep 24, 7:25 am)
Re: OBSD's perspective on SELinux, Chris Kuethe, (Mon Sep 24, 7:52 am)
Re: OBSD's perspective on SELinux, Brian Candler, (Mon Sep 24, 8:31 am)
Re: OBSD's perspective on SELinux, Rui Miguel Silva Seabra, (Mon Sep 24, 8:59 am)
Re: OBSD's perspective on SELinux, Ted Unangst, (Mon Sep 24, 10:29 am)
Re: OBSD's perspective on SELinux, Jacob Yocom-Piatt, (Mon Sep 24, 11:17 am)
Re: OBSD's perspective on SELinux, ttw+bsd, (Mon Sep 24, 11:28 am)
Re: OBSD's perspective on SELinux, Ted Unangst, (Mon Sep 24, 12:14 pm)
Re: OBSD's perspective on SELinux, Damien Miller, (Mon Sep 24, 8:09 pm)
Re: OBSD's perspective on SELinux, Marc Espie, (Tue Sep 25, 3:06 am)
Re: OBSD's perspective on SELinux, Marc Espie, (Tue Sep 25, 5:34 am)