Research
.
Skip Search Box

SELinux Mailing List

Re: FYI SELinux/AppArmor press

From: coderman <coderman_at_gmail.com>
Date: Fri, 3 Mar 2006 08:50:08 -0800


On 3/3/06, Erich Schubert <erich@debian.org> wrote:
> ...
> I agree that this is a good approach. However, this can still be solved
> by inheritance. For example, you could grant webalizer access to
> apache_logfiles, which is actually an "abstract" type, realized by two
> other types "apache_access_logs" and "apache_error_logs".

inheritance and least privilege is difficult; this might be something to discuss in more detail with a constraint model applied to ensure that an inheritance hierarchy does not leak excessive and unnecessary privileges. has this been discussed before on the devel list?

"Integrated constraints and inheritance in DTAC" http://portal.acm.org/citation.shtml?id=344307

"The Role-Based Access Control System of a European Bank: A Case Study and Discussion"
http://www-users.cs.york.ac.uk/~jeremy/papers/SACMAT2001.pdf

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 3 Mar 2006 - 11:50:17 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service