1 |
On Tue, 9 May 2006, dante wrote: |
2 |
|
3 |
> On Tue, 2006-05-09 at 05:21 +0300, Alex Efros wrote: |
4 |
> > Hi! |
5 |
> > |
6 |
> > On Mon, May 08, 2006 at 07:26:54PM -0400, Ned Ludd wrote: |
7 |
> > > > * How do I make a policy? |
8 |
> > > > * Are there reference policies? In that case, where can I get them? |
9 |
> > > > * How do I check a policy for correctness? |
10 |
> > > > * Where can I find more documentation (I found more documentation on |
11 |
> > > > the kernel side of things than on the access control)? |
12 |
> > > Your questions would start a huge thread if we begun at this level |
13 |
> > > without you doing some homework first. |
14 |
> > |
15 |
> > Yeah. But I don't think it's bad idea. Problem with RBAC and grlearn is |
16 |
> > what there no single place with comprehensive yet simple enough HOWTO's, |
17 |
> > policy examples, etc. |
18 |
> |
19 |
> I also agree. There's also the situation where, after grlearn has |
20 |
> created policies the user may want to tweak them. I found this to be |
21 |
> the case with sshd where grlearn didn't set up the correct access and I |
22 |
> cut myself off when switching from learning to enforcing! |
23 |
|
24 |
that is probably your fault, you have to make at least one connection over |
25 |
sshd in the learning phase to get an entry for it (and remove the IP |
26 |
dependency if you want to get the connectivity through ssh from other IP |
27 |
addresses) |
28 |
|
29 |
Peter |
30 |
|
31 |
-- |
32 |
gentoo-hardened@g.o mailing list |