Research Menu

.
Skip Search Box

SELinux Mailing List

Re: Multiple contexts

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Tue, 11 Jan 2005 15:09:51 -0500


On Mon, 2005-01-10 at 18:23, Luke Kenneth Casson Leighton wrote:
> i can only hazard a hazardous guess therefore that the more
> "normal" ACL system [that we are used to seeing] was rejected
> because it makes the formal proof methodology more difficult.

With ACLs, you have to traverse the entire filesystem state in order to: 1) determine what your policy truly is (and that policy can change underneath you during your traversal),
2) apply any widespread changes in policy state.

Management and scalability nightmare.

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 11 Jan 2005 - 15:15:52 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service