SECURITY: NSA Security-enhanced Linux updated

From: Howard Holm (hdholm_at_epoch.ncsc.mil)
Date: 12/05/03


Date: Fri, 5 Dec 2003 14:31:57 CST

The SELinux web site <http://www.nsa.gov/selinux/> including the mail
list archive has been updated. The site includes a new release of the
LSM-based SELinux prototype. The base kernel versions have been updated
to 2.4.23 and 2.6.0-test11. In 2.6.0-test11 controls have been added for
inheritance of signal-related state and resource limits and the network
interface and node controls have been reimplemented. SysVinit has been
patched to eliminate the need for a modified initrd. Login now uses a
pam_selinux module. Many other updates have been made to the tools,
utilities and userland patches.

Security-enhanced Linux incorporates a strong, flexible mandatory
access control architecture into the major subsystems of the Linux
kernel. The system provides a mechanism to enforce the separation of
information based on confidentiality and integrity requirements. This
allows threats of tampering and bypassing of application security
mechanisms to be addressed and enables the confinement of damage that
can be caused by malicious or flawed applications. The SELinux web
site <http://www.nsa.gov/selinux/> contains background information,
documentation, source code, and archives for the selinux mailing-list.

-- 
Howard Holm <hdholm@epoch.ncsc.mil>
Office of Defensive Computing Research
National Security Agency
##########################################################################
# Send submissions for comp.os.linux.announce to: cola@stump.algebra.com #
# PLEASE remember a short description of the software and the LOCATION.  #
# This group is archived at http://stump.algebra.com/~cola/              #
##########################################################################


Relevant Pages

  • SECURITY: NSA Security-enhanced Linux updated
    ... The SELinux web site has been updated. ... prototype and the experimental NFS code are now based on Linux kernel ... The old linux 2.4-based kernel patch has ... allows threats of tampering and bypassing of application security ...
    (comp.os.linux.announce)
  • SECURITY: NSA Security-enhanced Linux updated
    ... The SELinux web site including the mail ... The base kernel versions have been ... National Security Agency ...
    (comp.os.linux.announce)
  • SECURITY: NSA Security-enhanced Linux updated
    ... The SELinux web site including the mail ... site contains background information, ... National Security Agency ...
    (comp.os.linux.announce)