Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #242640

Re: Don't try this at home kids

From Nicholas Geovanis <nickgeovanis@gmail.com>
Newsgroups linux.debian.user
Subject Re: Don't try this at home kids
Date 2021-12-03 05:50 +0100
Message-ID <Dq8Gd-85t-3@gated-at.bofh.it> (permalink)
References <DoZbX-7oy-5@gated-at.bofh.it> <Dp2Wd-1bt-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Mon, Nov 29, 2021, 10:27 PM Tom Dial <tddial@comcast.net> wrote:

>
>
> On 11/29/21 17:19, Nicholas Geovanis wrote:
> > On Mon, Nov 29, 2021, 5:14 PM James H. H. Lampert <
> jamesl@touchtonecorp.com <mailto:jamesl@touchtonecorp.com>> wrote:
> >
> >     .... And the only
> >     reason ROOT access is more dangerous than, say, QSECOFR access on
> OS/400
> >     (or whatever IBM is calling it this week) is because there's nothing
> >     stopping a Linux ROOT from doing things *nobody* should be allowed
> to do
> >     without putting the system into some kind of maintenance mode.
> >
> >
> > Well selinux stops root from doing those things. But im the only known
> human who doesn't dislike selinux. And other problems I have....
> > :-D
>
> You are not the only one who doesn't dislike or maybe even likes selinux.
> I consider it technically superior to apparmor as a mandatory access
> control system, and maybe both more flexible and user-friendlier as well. I
> found it generally fairly easy to find good documentation (e. g., Red Hat).
>

Redhat's doc is probably the best. But they ship it in several
pre-configured but non-complete base configurations. Like their "targeted
mode".

And I expect those who originated it, some still employed at USNSA, also
> think well of it, along with the current maintainers and likely enough
> quite a few other users.
>

The "rainbow books" are freely available on Google books nowadays. They
were NCSC (NSA) guidelines for highly secure govt systems. I implemented B1
level security (Orange book, Green book) (MAC like selinux) in 1990 in Unix
OS's. Went thru the evaluation process with them.

Regards,
> Tom Dial
>
> >
> >
> >     .......
> >     --
> >     JHHL
> >
>
>

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Don't try this at home kids Bob Bernstein <poobah@ruptured-duck.com> - 2021-11-29 23:40 +0100
  Re: Don't try this at home kids Jeremy Ardley <jeremy@ardley.org> - 2021-11-29 23:50 +0100
    Re: Don't try this at home kids Jude DaShiell <jdashiel@panix.com> - 2021-11-29 23:50 +0100
      Re: Don't try this at home kids David Wright <deblis@lionunicorn.co.uk> - 2021-11-30 05:50 +0100
        Re: Don't try this at home kids Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2021-11-30 07:00 +0100
          Re: Don't try this at home kids Paul Johnson <baloo@ursamundi.org> - 2021-11-30 18:20 +0100
            Re: Don't try this at home kids Greg Wooledge <greg@wooledge.org> - 2021-11-30 19:20 +0100
              Re: Don't try this at home kids David Wright <deblis@lionunicorn.co.uk> - 2021-12-03 03:50 +0100
            Re: Don't try this at home kids Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2021-11-30 20:40 +0100
              Re: Don't try this at home kids Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-05 16:40 +0100
        Re: Don't try this at home kids Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-05 16:50 +0100
    Re: Don't try this at home kids Darac Marjal <mailinglist@darac.org.uk> - 2021-11-30 00:00 +0100
    Re: Don't try this at home kids "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2021-11-30 00:20 +0100
      Re: Don't try this at home kids Jeremy Ardley <jeremy@ardley.org> - 2021-11-30 00:30 +0100
      Re: Don't try this at home kids John Hasler <john@sugarbit.com> - 2021-11-30 01:10 +0100
      Re: Don't try this at home kids Bob Bernstein <poobah@ruptured-duck.com> - 2021-11-30 01:10 +0100
      Re: Don't try this at home kids Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-11-30 01:30 +0100
        Re: Don't try this at home kids Tom Dial <tddial@comcast.net> - 2021-11-30 05:30 +0100
          Re: Don't try this at home kids Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-03 05:50 +0100
  Re: Don't try this at home kids Igor Korot <ikorot01@gmail.com> - 2021-11-30 00:00 +0100
  Re: Don't try this at home kids Pierre-Elliott Bécue <peb@debian.org> - 2021-11-30 00:00 +0100

csiph-web