1 |
On Sunday 23 March 2008, Alon Bar-Lev wrote: |
2 |
> linux-2.6.24 supports file based capabilities via: |
3 |
> CONFIG_SECURITY_FILE_CAPABILITIES |
4 |
> |
5 |
> This enables the use of filesystem attributes in order to store per |
6 |
> executable capabilities list, more information at [1]. |
7 |
> |
8 |
> This enables improved security level for people who don't wish to move |
9 |
> into SELinux or similar. |
10 |
> |
11 |
> I think a new global USE flags (or use current caps) may enable |
12 |
> ebuilds to set correct capabilities on files. |
13 |
|
14 |
Diego and i were talking ... we're going to go with USE=filecaps because it's |
15 |
so new and doesnt require the libcap library in order to work at runtime. |
16 |
probably be worthwhile to put together a little eclass of functions to make |
17 |
people's lives easier ... |
18 |
-mike |