Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] load_policy
Date: Tue, 31 Jul 2007 13:06:22
Message-Id: 1185887019.5062.20.camel@defiant.pebenito.net
In Reply to: [gentoo-hardened] load_policy by John Huttley
1 On Tue, 2007-07-31 at 13:32 +1200, John Huttley wrote:
2 > Wandering through the man pages, i've found load_policy and checkpolicy
3 >
4 > Have they been obsoleted by semodule ?
5
6 No, checkpolicy is still used if one wants to built a monolithic policy.
7 High assurance systems (like government systems, for example) generally
8 have static policy since the system doesn't change; thus, building a
9 monolithic policy makes sense still. Most other people have more
10 dynamic systems that change as you add/remove/upgrade packages and make
11 more sense being modular.
12
13 Load_policy is called by semodule, to load the policy into the kernel.
14
15 --
16 Chris PeBenito
17 <pebenito@g.o>
18 Developer,
19 Hardened Gentoo Linux
20
21 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
22 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature