* Re: Sealing the kernel
@ 1999-10-26 19:28 Jesse Pollard
0 siblings, 0 replies; only message in thread
From: Jesse Pollard @ 1999-10-26 19:28 UTC (permalink / raw)
To: linux-kernel
>From: Aaron Sethman <androsyn@atomic-city.dev.powerize.com>
>On Tue, 26 Oct 1999, Dimitris Margaritis wrote:
>> Yes, John forgot to mention that we're assuming boot from a read-only
>> media such as a write-protected floppy or CD-ROM. We also assume
>> that the rc scripts, kernel, and all modules to be loaded at boot
>> time (before of course the sealing module) also reside on that medium.
>>
>> About your last point, yes, root can do a lot of nasty things, but by
>> sealing the kernel at least they are constrained to what's available
>> through kernel services. That may help presumably by disabling a lot
>> of stuff in the running kernel.
>Or even a better idea, compile the kernel without module support all
>together. Just hope that you don't have any of those blasted Plug and
>Pray devices.
It would be better (in general) to remove root as a privileged user.
Try
http://www.rsbac.de/rsbac/
for a possible implementation.
-------------------------------------------------------------------------
Jesse I Pollard, II
Email: pollard@navo.hpc.mil
Any opinions expressed are solely my own.
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~1999-10-26 20:07 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
1999-10-26 19:28 Sealing the kernel Jesse Pollard
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®