Gentoo Archives: gentoo-hardened

From: dante <dante@×××××××××××××××.net>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] How do I use grSecurity mandatory access control?
Date: Tue, 09 May 2006 11:22:28
Message-Id: 1147173594.8086.10.camel@white.dis
In Reply to: Re: [gentoo-hardened] How do I use grSecurity mandatory access control? by Alex Efros
1 On Tue, 2006-05-09 at 05:21 +0300, Alex Efros wrote:
2 > Hi!
3 >
4 > On Mon, May 08, 2006 at 07:26:54PM -0400, Ned Ludd wrote:
5 > > > * How do I make a policy?
6 > > > * Are there reference policies? In that case, where can I get them?
7 > > > * How do I check a policy for correctness?
8 > > > * Where can I find more documentation (I found more documentation on
9 > > > the kernel side of things than on the access control)?
10 > > Your questions would start a huge thread if we begun at this level
11 > > without you doing some homework first.
12 >
13 > Yeah. But I don't think it's bad idea. Problem with RBAC and grlearn is
14 > what there no single place with comprehensive yet simple enough HOWTO's,
15 > policy examples, etc.
16
17 I also agree. There's also the situation where, after grlearn has
18 created policies the user may want to tweak them. I found this to be
19 the case with sshd where grlearn didn't set up the correct access and I
20 cut myself off when switching from learning to enforcing!
21
22 I'd be willing to take a first stab at a howto in about one week. I'm i
23 the middle of giving and grading exams right now. Anyone else
24 interested?
25
26 Anthony Basile,
27 Chair of IT
28 D'Youville College
29 Buffalo NY, 14201
30
31
32 --
33 gentoo-hardened@g.o mailing list

Replies