mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: James Morris <jmorris@namei.org>
To: David Howells <dhowells@redhat.com>
Cc: Chris Wright <chrisw@osdl.org>, Andrew Morton <akpm@osdl.org>,
	Linus Torvalds <torvalds@osdl.org>,
	keyrings@linux-nfs.org, linux-kernel@vger.kernel.org,
	Stephen Smalley <sds@tycho.nsa.gov>
Subject: Re: [Keyrings] [PATCH] Keys: Add LSM hooks for key management
Date: Thu, 6 Oct 2005 11:04:50 -0400 (EDT)	[thread overview]
Message-ID: <Pine.LNX.4.63.0510061053180.26758@excalibur.intercode> (raw)
In-Reply-To: <23333.1128596048@warthog.cambridge.redhat.com>

On Thu, 6 Oct 2005, David Howells wrote:

> > Agree, in fact, I think we should always aim to keep housekeeping hooks 
> > separate from access control hooks.
> 
> What do you mean by separate? And this provides a chance for the LSM to deny
> the creation of a key before it's published.

Separate in terms of providing clear semantics in the API, so that you 
know a hook is either used for housekeeping (allocation, deallocation etc) 
or for access control.  But this is only an aim, an if it makes sense to 
combine housekeeping and access control functions in some specific 
instance, then so be it.


> > Access checks seem to be usually done before this point via 
> > lookup_user_key(), which is ideal.
> 
> Eh? lookup_user_key()? That's not necessarily called before, not if you're
> creating a key.

I thought this was generally called before key operations.

For example, sys_add_key() calls it with KEY_WRITE against the destination 
keyring.

> > > This is odd, esp since nothing could have failed between alloc and
> > > publish.  Only state change is serial number.  Would you expect the
> > > security module to update a label based on serial number?
> > 
> > I don't think SELinux would care about this yet.  If so, the hook can be 
> > added later.
> 
> Auditing?

SELinux does not audit object creation, it will sometimes use a _post hook 
to update its internal state or perform the access control check for 
creating the object.


- James
-- 
James Morris
<jmorris@namei.org>

  reply	other threads:[~2005-10-06 15:04 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-10-05 16:28 David Howells
2005-10-05 16:44 ` [Keyrings] " James Morris
2005-10-05 16:48 ` David Howells
2005-10-05 19:31   ` James Morris
2005-10-05 18:40 ` serue
2005-10-05 21:10 ` [Keyrings] " Chris Wright
2005-10-06  8:03   ` James Morris
2005-10-06 10:54   ` David Howells
2005-10-06 15:04     ` James Morris [this message]
2005-10-06 15:18     ` David Howells
2005-10-06 16:02       ` James Morris
2005-10-07  8:50       ` David Howells
2005-10-07 18:36         ` Chris Wright
2005-10-06 17:58     ` Chris Wright
2005-10-07  9:10     ` David Howells
2005-10-07 12:59       ` Stephen Smalley
2005-10-07 18:51       ` Chris Wright
2005-10-06  8:38 ` James Morris
2005-10-06 10:30 ` David Howells
2005-10-06 23:10   ` Chris Wright
2005-10-07  9:57   ` David Howells
2005-10-07 19:36     ` Chris Wright
2005-10-06 11:06 ` David Howells
2005-10-06 14:25   ` James Morris
2005-10-06 15:11   ` David Howells
2005-10-06 16:14     ` James Morris
2005-10-07  9:03     ` David Howells
2005-10-07 14:05       ` James Morris

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Pine.LNX.4.63.0510061053180.26758@excalibur.intercode \
    --to=jmorris@namei.org \
    --cc=akpm@osdl.org \
    --cc=chrisw@osdl.org \
    --cc=dhowells@redhat.com \
    --cc=keyrings@linux-nfs.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=sds@tycho.nsa.gov \
    --cc=torvalds@osdl.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome