1 |
Hi! |
2 |
|
3 |
On Mon, May 08, 2006 at 07:26:54PM -0400, Ned Ludd wrote: |
4 |
> > * How do I make a policy? |
5 |
> > * Are there reference policies? In that case, where can I get them? |
6 |
> > * How do I check a policy for correctness? |
7 |
> > * Where can I find more documentation (I found more documentation on |
8 |
> > the kernel side of things than on the access control)? |
9 |
> Your questions would start a huge thread if we begun at this level |
10 |
> without you doing some homework first. |
11 |
|
12 |
Yeah. But I don't think it's bad idea. Problem with RBAC and grlearn is |
13 |
what there no single place with comprehensive yet simple enough HOWTO's, |
14 |
policy examples, etc. |
15 |
|
16 |
> learning modes. It's quite intuitive to administer once you get the |
17 |
> initial hang of it. |
18 |
|
19 |
You right!!! After I try learning mode first time I found it very |
20 |
intuitive... but after I've activated rules produced by "learning mode" |
21 |
my system "hang" and I have to press RESET button. :) |
22 |
|
23 |
So I delay learning how to use learning mode without locking my system |
24 |
for better time. :( |
25 |
|
26 |
So, if somebody will summarize all documentation sources you mention - |
27 |
I'll be really happy. |
28 |
|
29 |
P.S. I _had_ read both urls you mention, at least three times each, :) |
30 |
and searched google/gmane too, but this was about year ago. |
31 |
|
32 |
P.P.S. AFAIK SELinux has much more rich documentation and a lot of |
33 |
predefined policy, but my intuition says what there something wrong |
34 |
with SELinux and I prefer to use RBAC as soon as I found enough |
35 |
documentation. (I don't used SELinux myself, so probably my intuition |
36 |
feeling based mostly on articles/posts readed on GrSecurity-related sites |
37 |
and some posts about SELinux in this maillist...) |
38 |
|
39 |
-- |
40 |
WBR, Alex. |
41 |
-- |
42 |
gentoo-hardened@g.o mailing list |