Research Menu

.
Skip Search Box

SELinux Mailing List

Re: [patch] enhanced MLS support

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Mon, 24 Jan 2005 07:30:24 -0500


On Sun, 2005-01-23 at 22:40, Casey Schaufler wrote:
> I would think that you couldn't call the
> system flexible in any meaningful way if
> it couldn't accomodate an integrity policy.
> The Trix experience is that Biba integrity
> is overkill. A binary integrity policy
> distinguishing between TCB and User data and
> processes is useful, but going beyond that
> adds more complexity than anyone (sane) is
> going to want to deal with.

TE is preferable for integrity protection. IMHO, there is no need to introduce a Biba model to SELinux.

> Erg. Or handling caveats? Actually, the
> above comment regarding the flexibility of
> the system applies. If the system can't be
> demonstrated to handle these, it probably
> isn't very agile.

Should be expressible using the category bitmaps.

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 24 Jan 2005 - 07:36:44 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service