Gentoo Archives: gentoo-hardened

From: "Peter S. Mazinger" <ps.m@×××.net>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] How do I use grSecurity mandatory access control?
Date: Sat, 13 May 2006 20:51:02
Message-Id: Pine.LNX.4.44.0605132242040.10710-100000@lnx.bridge.intra
In Reply to: Re: [gentoo-hardened] How do I use grSecurity mandatory access control? by dante
1 On Tue, 9 May 2006, dante wrote:
2
3 > On Tue, 2006-05-09 at 05:21 +0300, Alex Efros wrote:
4 > > Hi!
5 > >
6 > > On Mon, May 08, 2006 at 07:26:54PM -0400, Ned Ludd wrote:
7 > > > > * How do I make a policy?
8 > > > > * Are there reference policies? In that case, where can I get them?
9 > > > > * How do I check a policy for correctness?
10 > > > > * Where can I find more documentation (I found more documentation on
11 > > > > the kernel side of things than on the access control)?
12 > > > Your questions would start a huge thread if we begun at this level
13 > > > without you doing some homework first.
14 > >
15 > > Yeah. But I don't think it's bad idea. Problem with RBAC and grlearn is
16 > > what there no single place with comprehensive yet simple enough HOWTO's,
17 > > policy examples, etc.
18 >
19 > I also agree. There's also the situation where, after grlearn has
20 > created policies the user may want to tweak them. I found this to be
21 > the case with sshd where grlearn didn't set up the correct access and I
22 > cut myself off when switching from learning to enforcing!
23
24 that is probably your fault, you have to make at least one connection over
25 sshd in the learning phase to get an entry for it (and remove the IP
26 dependency if you want to get the connectivity through ssh from other IP
27 addresses)
28
29 Peter
30
31 --
32 gentoo-hardened@g.o mailing list