1 |
On Tue, 9 May 2006, Alex Efros wrote: |
2 |
|
3 |
> Hi! |
4 |
> |
5 |
> On Mon, May 08, 2006 at 07:26:54PM -0400, Ned Ludd wrote: |
6 |
> > > * How do I make a policy? |
7 |
> > > * Are there reference policies? In that case, where can I get them? |
8 |
> > > * How do I check a policy for correctness? |
9 |
> > > * Where can I find more documentation (I found more documentation on |
10 |
> > > the kernel side of things than on the access control)? |
11 |
> > Your questions would start a huge thread if we begun at this level |
12 |
> > without you doing some homework first. |
13 |
> |
14 |
> Yeah. But I don't think it's bad idea. Problem with RBAC and grlearn is |
15 |
> what there no single place with comprehensive yet simple enough HOWTO's, |
16 |
> policy examples, etc. |
17 |
> |
18 |
> > learning modes. It's quite intuitive to administer once you get the |
19 |
> > initial hang of it. |
20 |
> |
21 |
> You right!!! After I try learning mode first time I found it very |
22 |
> intuitive... but after I've activated rules produced by "learning mode" |
23 |
> my system "hang" and I have to press RESET button. :) |
24 |
> |
25 |
> So I delay learning how to use learning mode without locking my system |
26 |
> for better time. :( |
27 |
> |
28 |
> So, if somebody will summarize all documentation sources you mention - |
29 |
> I'll be really happy. |
30 |
> |
31 |
> P.S. I _had_ read both urls you mention, at least three times each, :) |
32 |
> and searched google/gmane too, but this was about year ago. |
33 |
> |
34 |
> P.P.S. AFAIK SELinux has much more rich documentation and a lot of |
35 |
> predefined policy, but my intuition says what there something wrong |
36 |
> with SELinux and I prefer to use RBAC as soon as I found enough |
37 |
> documentation. (I don't used SELinux myself, so probably my intuition |
38 |
> feeling based mostly on articles/posts readed on GrSecurity-related sites |
39 |
> and some posts about SELinux in this maillist...) |
40 |
|
41 |
I have some "predefined policies" but I haven't ever tested them in a |
42 |
pure gentoo environment (I do not use gentoo in "production environment"), |
43 |
if you want them as startup and will provide the gentoo counterparts, I |
44 |
will send them to you (read the earlier __carefully__, if you are not |
45 |
able/not willing to provide them, then it was the last time I am doing |
46 |
this, I am not willing to support any of them and do any of the needed |
47 |
tests to work in conjunction w/ gentoo) |
48 |
|
49 |
Peter |
50 |
|
51 |
-- |
52 |
Peter S. Mazinger <ps dot m at gmx dot net> ID: 0xA5F059F2 |
53 |
Key fingerprint = 92A4 31E1 56BC 3D5A 2D08 BB6E C389 975E A5F0 59F2 |
54 |
|
55 |
-- |
56 |
gentoo-hardened@g.o mailing list |