Re: [PATCH] 3 of 5 IMA: LSM-based measurement code

From: Serge E. Hallyn (serue_at_us.ibm.com)
Date: 06/16/05

  • Next message: Reiner Sailer: "Re: [PATCH] 3 of 5 IMA: LSM-based measurement code"
    Date:	Wed, 15 Jun 2005 17:42:41 -0500
    To: Chris Wright <chrisw@osdl.org>
    
    

    Quoting Chris Wright (chrisw@osdl.org):
    > * serue@us.ibm.com (serue@us.ibm.com) wrote:
    > > Quoting Chris Wright (chrisw@osdl.org):
    > > > The primary purpose of the hooks is access control. Some of them, of
    > > > course, are helpers to keep labels coherent. IIRC, James objected
    > > > because the measurement data was simply collected from these hooks.
    > >
    > > Ok, so to be clear, any module which does not directly impose some form
    > > of access control is not eligible for an LSM?
    >
    > That's exactly the intention, yes.

    Ok, thanks.

    I thought it was intended to be more general than that - in fact I
    specifically thought it was not intended to be purely for single machine
    authentication decisions within a single kernel module, but that anything
    which would aid in enabling new security features, locally or remotely,
    would be game. (Which - it means nothing - but I would clearly have
    preferred :)

    Thanks for setting me straight.

    -serge

    -
    To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
    the body of a message to majordomo@vger.kernel.org
    More majordomo info at http://vger.kernel.org/majordomo-info.html
    Please read the FAQ at http://www.tux.org/lkml/


  • Next message: Reiner Sailer: "Re: [PATCH] 3 of 5 IMA: LSM-based measurement code"

    Relevant Pages

    • Re: [PATCH] 3 of 5 IMA: LSM-based measurement code
      ... > of access control is not eligible for an LSM? ... In particular, an additional access control. ... stated eligibilty requirements. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [PATCH] 3 of 5 IMA: LSM-based measurement code
      ... Access control is a very broad term. ... like to make clear that I do not have a preference for or against LSM. ... IMA can help by being one modest building block ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [PATCH] 3 of 5 IMA: LSM-based measurement code
      ... > Access control is a very broad term. ... > like to make clear that I do not have a preference for or against LSM. ... > matter to the user where IMA will be located. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [1/1][PATCH] nproc v2: netlink access to /proc information
      ... - If the access control bits for a field are cleared, ... If an app asks for a field it has no or partial permission for, ... bitmaps or lists of applicaple fields or something) for one special ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [PATCH] [request for inclusion] Realtime LSM
      ... > need root to configure the LSM anyway.. ... Yes but a bug in an app running as root can trash the filesystem. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)