Research Menu

.
Skip Search Box

SELinux Mailing List

RE: [RFC] [PATCH 4/4] SELinux changes

From: Venkatesh Yekkirala <vyekkirala_at_TrustedCS.com>
Date: Wed, 19 Sep 2007 16:22:24 -0500


> -----Original Message-----
> From: James Morris [mailto:jmorris@namei.org]
> Sent: Wednesday, September 19, 2007 4:13 PM
> To: Stephen Smalley
> Cc: Venkat Yekkirala; selinux@tycho.nsa.gov; paul.moore@hp.com; Karl
> MacMillan; Joshua Brindle
> Subject: Re: [RFC] [PATCH 4/4] SELinux changes
>
>
> On Wed, 19 Sep 2007, Stephen Smalley wrote:
>
> > We thought we were eliminating the need for these per-packet
> > per-node/netif checks by way of secmark, but I guess not if we are
> > keeping secmark separate from labeled networking.
>
> The checks should only be made if labeled networking is active.

Actually even when we aren't using labeled networking, we would want to prevent packets arriving on a top-secret interface from being forwarded onto a secret interface. So, the checks would be in order here as well.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Wed 19 Sep 2007 - 17:22:57 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service