public inbox for gentoo-hardened@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-hardened] SELinux policy rules principles?
@ 2011-01-16 15:09 Sven Vermeulen
  2011-01-16 17:06 ` Chris Richards
       [not found] ` <4D33455B.8050708@users.sourceforge.net>
  0 siblings, 2 replies; 10+ messages in thread
From: Sven Vermeulen @ 2011-01-16 15:09 UTC (permalink / raw
  To: gentoo-hardened

Hi all,

When writing security policies, it is important to first have a vision on
how the security policies should be made. Of course, final vision should be
with a systems' security administrator, but a distribution should give a
first start for this.

For the time being, Gentoo Hardened's policies are based upon the reference
policy's implementation, but I can imagine that this will evolve further.
The moment however we start adding policies ourselves (outside simple
patching of the reference policy's implementation) we need to have some
rules on what or how our rules should be made.

One first principle that we might need to discuss about is what we want to
allow in our policy. Do we want to allow all normal behavior (i.e. you use
an application or server the way it is meant to and we make sure no denials
are generated for this) but shield off abnormal behavior as much as possible
(by rightly aligning domains and types)? Or do we want to allow just enough
so that the applications function properly during regular operations,
causing various denials to be in place still?

And if we would opt for the latter, do we want to dontaudit those denials to
keep the logging clean, or do we then expect the administrator to manage his
own dontaudits?

Wkr,
       Sven Vermeulen



^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2011-01-21 22:46 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-01-16 15:09 [gentoo-hardened] SELinux policy rules principles? Sven Vermeulen
2011-01-16 17:06 ` Chris Richards
2011-01-19 19:39   ` Sven Vermeulen
2011-01-19 20:05     ` Chris Richards
2011-01-19 20:25       ` Sven Vermeulen
2011-01-19 20:34         ` Chris Richards
2011-01-21 21:55   ` Sven Vermeulen
2011-01-21 22:12     ` klondike
2011-01-21 22:43     ` Chris Richards
     [not found] ` <4D33455B.8050708@users.sourceforge.net>
2011-01-19 19:54   ` Sven Vermeulen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox