Home Messages Index
[Date Prev][Date Next][Thread Prev][Thread Next]
Author IndexDate IndexThread Index

Re: [News] Linux Security Compared to a 'Gold Standard' (OpenBSD)

  • Subject: Re: [News] Linux Security Compared to a 'Gold Standard' (OpenBSD)
  • From: "[H]omer" <spam@xxxxxxx>
  • Date: Thu, 27 Sep 2007 05:53:04 +0100
  • Bytes: 2817
  • In-reply-to: <2258764.aHrybGE68t@xxxxxxxxxxxxxxx>
  • Newsgroups: comp.os.linux.advocacy
  • Openpgp: id=BF436EC9; url=http://slated.org/files/GPG-KEY-SLATED.asc
  • Organization: Slated.org
  • References: <2258764.aHrybGE68t@xxxxxxxxxxxxxxx>
  • User-agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.8.1.6) Gecko/20070811 Remi/2.0.0.6-1.fc6.remi Thunderbird/2.0.0.6 Mnenhy/0.7.5.666
  • Xref: ellandroad.demon.co.uk comp.os.linux.advocacy:562780
Verily I say unto thee, that Roy Schestowitz spake thusly:
> SELinux vs. OpenBSD's Default Security
> 
> ,----[ Quote ]
> | Darrin Chandler suggested, "security should not be grafted on, it 
> | should be integrated into the main development process. I'm sure 
> | the patch maintainers are doing their best, but this doesn't change
> | the fundamental flaw in the process. It's not a flaw of their
> | making, it's inherent in the situation. But it's still a flaw."
> `----

Whilst I agree that SELinux is overly complex, it is nonetheless a
robust solution when properly deployed and maintained.

The key to simplifying SELinux integration is for each package
maintainer to distribute a policy addendum for that package, thus
ensuring the contexts for that package are properly set.

This is not especially difficult, other than requiring an addition
testing phase for each package, and can be deployed in the RPM/DEB.

If package maintainers would adopt and follow that procedure, most of
the difficulties and criticisms regarding SELinux would disappear,
packages would "just work" with SELinux enabled, and nobody would feel
compelled to automatically disable SELinux at the first sign of
difficulty.

This does not preclude security being "part of code quality, and part of
the normal mainline development", as he later asserts. The two are not
mutually exclusive.

-- 
K.
http://slated.org

.----
| "OOXML is a superb standard"
| - GNU/Linux traitor, Miguel de Icaza.
`----

Fedora release 7 (Moonshine) on sky, running kernel 2.6.22.1-41.fc7
 05:51:19 up 49 days,  4:46,  3 users,  load average: 0.57, 0.33, 0.39

[Date Prev][Date Next][Thread Prev][Thread Next]
Author IndexDate IndexThread Index