Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandatory Access Control Kernel



Andi Kleen wrote:
- hm, netlabels. Who might be a suitable person to review that code?
Seems that Paul Moore is the man. Maybe he'd be interested in taking a
look over it (please?)

I personally consider these IP options it uses to be pretty useless. Who could ever use that without cryptographic authentication? Clearly when they were designed in the original IP spec long ago the designers didn't understand
network security very well because the whole field was at its infancy. And CIPSO doesn't solve any of these fundamental issues.

It assumes a trusted network which is a very dangerous assumption. I don't think that was in the original patch I looked at, I surely would have objected to it.

Perhaps take the network part out? I guess SMACK would be useful
locally even without questionable network support.

CIPSO is supported on SELinux as well. It certainly has uses where IPSec is excessive. One example is someone I talked to recently that basically has a set of blade systems connected with a high speed backplane that looks like a network interface. CIPSO is useful in this case because they can't afford the overhead of IPSec but need to transfer the level of the connection to the other machines. The backplane is a trusted network and that isn't a dangerous assumption in this case.

CIPSO also lets systems like SELinux and SMACK talk to other trusted systems (eg., trusted solaris) in a way they understand. I don't regularly support CIPSO as I believe IPSec labeling is more useful in more situations but that doesn't mean CIPSO is never useful.

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/



Relevant Pages

  • Re: SMACK netfilter smacklabel socket match
    ... MAC systems wouldn't be surprised by that. ... a machine that doesn't talk CIPSO and hence Smack is treating all ... If I set /smack/nltype to 'unlabeled' I have effectively shut off the network. ... Labeled processes produce CIPSO labeled packets ...
    (Linux-Kernel)
  • Re: SOHO 6tc Wireless
    ... devices on the trusted/ wired side of the network. ... are connected using a manual VPN connection between the SOHO's ... and the idea was to get a laptop to access ... network and it does not allow any access to the trusted network. ...
    (comp.security.firewalls)
  • Re: Watchguard Firebox III 700: ARP/DHCP problem?!?
    ... Watchguard line has a known issue with certain auto switches/Routers. ... > the few servers on the optional network have static ip configuration. ... > on the trusted network all clients are configured via dhcp from a w2k ... if i clear the arp cache of the wg firebox by using ...
    (comp.security.firewalls)
  • RE: [fw-wiz] Rationale of the great DMZ
    ... to use their trusted network. ... Not the secure network is becoming more operationally architected ... these people from the trusted network, they have more lax outbound policies ... gotomypc or any peer to peer application (at least the ones they know how ...
    (Firewall-Wizards)
  • Re: SMACK netfilter smacklabel socket match
    ... If I set /smack/nltype to 'unlabeled' I have effectively shut off the network. ... set the nltype to anything other than CIPSO at least for the time being. ... I strongly advice for a way to omit netlabel based access control. ...
    (Linux-Kernel)