Research
.
Skip Search Box

SELinux Mailing List

Re: dynamic context transitions

From: Luke Kenneth Casson Leighton <lkcl_at_lkcl.net>
Date: Thu, 4 Nov 2004 17:25:47 +0000


On Thu, Nov 04, 2004 at 11:50:19AM -0500, Stephen Smalley wrote:
> On Wed, 2004-11-03 at 12:26, Luke Kenneth Casson Leighton wrote:
> > the problem that SELinux faces is that as soon as you provide a
> > seteuid-like function as a "sop" to help people adopt SElinux
> > in applications, all bets are off for being able to remove
> > it at a later date, and SELinux's security assurance is lost.
>
> I don't think that this is a fair statement

 i am happy to be corrected.

> I would like to move forward with this proposal, going beyond a
> discussion of whether or not it should be implemented to how

 cool. elrond [samba-tng] is happy to create a real-world test  of any such implementation.

 l.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 4 Nov 2004 - 12:15:12 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service