Re: OBSD's perspective on SELinux

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Monday, September 24, 2007 - 11:59 am

Hi,

On Mon, Sep 24, 2007 at 04:31:22PM +0100, Brian Candler wrote:

The guy can be some stupid binary software with an "if(uid!=root) bail();"

> - You set file permissions so this userid can read only the file of interest

"none else" => find / -type f -exec chmod o-r \{\} \; is a lot of overkill....

> - You use pf rules so that this user ID cannot send network packets

All in all, forms of doing it all, but doing all you described creates a lot
more work than creating an SELinux policy :)

Best,
Rui

--
Umlaut Zebra o?=ber alles!
Today is Boomtime, the 48th day of Bureaucracy in the YOLD 3173
+ No matter how much you do, you never do enough -- unknown
+ Whatever you do will be insignificant,
| but it is very important that you do it -- Gandhi
+ So let's do it...?

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 11:34 am)
Re: OBSD's perspective on SELinux, Damien Miller, (Mon Sep 24, 11:09 pm)
Re: OBSD's perspective on SELinux, Chris Kuethe, (Mon Sep 24, 10:52 am)
Re: OBSD's perspective on SELinux, Marco Peereboom, (Sat Sep 22, 11:27 pm)
Re: OBSD's perspective on SELinux, L. V. Lammert, (Sat Sep 22, 7:47 pm)
Re: OBSD's perspective on SELinux, Rui Miguel Silva Seabra, (Sun Sep 23, 5:54 pm)
Re: OBSD's perspective on SELinux, Ted Unangst, (Mon Sep 24, 1:29 pm)
Re: OBSD's perspective on SELinux, Jacob Yocom-Piatt, (Mon Sep 24, 2:17 pm)
Re: OBSD's perspective on SELinux, Ted Unangst, (Mon Sep 24, 3:14 pm)
Re: OBSD's perspective on SELinux, Brian Candler, (Mon Sep 24, 11:31 am)
Re: OBSD's perspective on SELinux, Rui Miguel Silva Seabra, (Mon Sep 24, 11:59 am)
Re: OBSD's perspective on SELinux, Marc Espie, (Tue Sep 25, 6:06 am)
Re: OBSD's perspective on SELinux, Marc Espie, (Tue Sep 25, 8:34 am)
Re: digitally signed distribution (was: OBSD's perspective o..., Martin Schröder, (Mon Sep 24, 11:18 am)
Re: digitally signed distribution (was: OBSD's perspective o..., Martin Schröder, (Mon Sep 24, 12:02 pm)
Re: digitally signed distribution (was: OBSD's perspective o..., Rui Miguel Silva Seabra, (Sun Sep 23, 6:38 pm)
Re: OBSD's perspective on SELinux, Ted Unangst, (Sat Sep 22, 2:50 pm)
Re: OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 4:21 pm)
Re: OBSD's perspective on SELinux, , (Sat Sep 22, 7:20 pm)
Re: OBSD's perspective on SELinux, Stuart Henderson, (Sat Sep 22, 4:00 pm)
Re: OBSD's perspective on SELinux, Joachim Schipper, (Sat Sep 22, 12:29 pm)
Re: OBSD's perspective on SELinux, Ihar Hrachyshka, (Sat Sep 22, 12:45 pm)
Re: OBSD's perspective on SELinux, Joachim Schipper, (Sat Sep 22, 4:39 pm)
Re: OBSD's perspective on SELinux, Darrin Chandler, (Sat Sep 22, 12:00 pm)
Re: OBSD's perspective on SELinux, Eduardo Tongson, (Sat Sep 22, 12:52 pm)
Re: OBSD's perspective on SELinux, Jason Dixon, (Sat Sep 22, 12:20 pm)
Re: OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 1:21 pm)
Re: OBSD's perspective on SELinux, Ihar Hrachyshka, (Sat Sep 22, 1:38 pm)
Re: OBSD's perspective on SELinux, David Gwynne, (Mon Sep 24, 10:08 am)
Re: OBSD's perspective on SELinux, Jason Dixon, (Mon Sep 24, 10:25 am)
Re: OBSD's perspective on SELinux, , (Mon Sep 24, 2:28 pm)
Re: OBSD's perspective on SELinux, Brian Candler, (Sun Sep 23, 3:25 pm)
Re: OBSD's perspective on SELinux, Eduardo Tongson, (Sat Sep 22, 2:00 pm)
Re: OBSD's perspective on SELinux, Jeffrey 'jf' Lim, (Sat Sep 22, 12:26 pm)