Research
.
Skip Search Box

SELinux Mailing List

Re: Security Officer and System Administrator Separation of Duties

From: Russell Coker <russell_at_coker.com.au>
Date: Sat, 4 Oct 2003 17:29:44 +1000


On Sat, 4 Oct 2003 00:53, Tom wrote:
> On Fri, Oct 03, 2003 at 09:32:33PM +1000, Russell Coker wrote:
> > I think that perhaps you misunderstood my message. My point is that
> > anyone who can write to programs such as fsck and run them in their usual
> > context can trivially bypass any other security restrictions.
>
> I get you.
>
> Yes, it appears that a good configuration will need a third role for
> software updates and machine-level configurations.

If that is the case then we need to fix the policy to allow multiple admin_domain() entries.

Currently no-one has written any policy that has more than one admin_domain, so the chances of that working are quite small.

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Sat 4 Oct 2003 - 03:30:07 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service