mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: James Morris <jmorris@namei.org>
To: David Howells <dhowells@redhat.com>
Cc: Chris Wright <chrisw@osdl.org>, Andrew Morton <akpm@osdl.org>,
	Linus Torvalds <torvalds@osdl.org>,
	keyrings@linux-nfs.org, linux-kernel@vger.kernel.org,
	Stephen Smalley <sds@tycho.nsa.gov>,
	Steve Grubb <sgrubb@redhat.com>
Subject: Re: [Keyrings] [PATCH] Keys: Add LSM hooks for key management
Date: Thu, 6 Oct 2005 12:02:57 -0400 (EDT)	[thread overview]
Message-ID: <Pine.LNX.4.63.0510061148250.26937@excalibur.intercode> (raw)
In-Reply-To: <30209.1128611882@warthog.cambridge.redhat.com>

On Thu, 6 Oct 2005, David Howells wrote:

> > For example, sys_add_key() calls it with KEY_WRITE against the destination 
> > keyring.
> 
> Yes, but not in regard to the new key, which is what I thought you were
> implying.
> 
> Besides, it's logically two operations: create key and link key to
> keyring. The reason they have to be combined is that the key would be
> immediately destroyed if it wasn't attached to a keyring.

I had assumed that you didn't want a permission check just for creating a 
key (which is a fairly abstract and inert thing if you don't do anything 
with it), and were only wanting to peform a check when linking.

> The permissions check done on the keyring merely assures that the keyring can
> be modified, not that a new key may or may not actually be created.

Ok, time to add KEY_CREATE?

> > > > I don't think SELinux would care about this yet.  If so, the hook can be 
> > > > added later.
> > > 
> > > Auditing?
> > 
> > SELinux does not audit object creation, it will sometimes use a _post hook 
> > to update its internal state or perform the access control check for 
> > creating the object.
> 
> I meant the auditing service. Doesn't that use the security module hooks?

LSM is supposed to be about access control only, although SELinux and 
Audit are becoming more intimate as time passes.

[added Steve Grubb to the cc list, who is looking at LSPP audit 
requirements]



- James
-- 
James Morris
<jmorris@namei.org>

  reply	other threads:[~2005-10-06 16:03 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-10-05 16:28 David Howells
2005-10-05 16:44 ` [Keyrings] " James Morris
2005-10-05 16:48 ` David Howells
2005-10-05 19:31   ` James Morris
2005-10-05 18:40 ` serue
2005-10-05 21:10 ` [Keyrings] " Chris Wright
2005-10-06  8:03   ` James Morris
2005-10-06 10:54   ` David Howells
2005-10-06 15:04     ` James Morris
2005-10-06 15:18     ` David Howells
2005-10-06 16:02       ` James Morris [this message]
2005-10-07  8:50       ` David Howells
2005-10-07 18:36         ` Chris Wright
2005-10-06 17:58     ` Chris Wright
2005-10-07  9:10     ` David Howells
2005-10-07 12:59       ` Stephen Smalley
2005-10-07 18:51       ` Chris Wright
2005-10-06  8:38 ` James Morris
2005-10-06 10:30 ` David Howells
2005-10-06 23:10   ` Chris Wright
2005-10-07  9:57   ` David Howells
2005-10-07 19:36     ` Chris Wright
2005-10-06 11:06 ` David Howells
2005-10-06 14:25   ` James Morris
2005-10-06 15:11   ` David Howells
2005-10-06 16:14     ` James Morris
2005-10-07  9:03     ` David Howells
2005-10-07 14:05       ` James Morris

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Pine.LNX.4.63.0510061148250.26937@excalibur.intercode \
    --to=jmorris@namei.org \
    --cc=akpm@osdl.org \
    --cc=chrisw@osdl.org \
    --cc=dhowells@redhat.com \
    --cc=keyrings@linux-nfs.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=sds@tycho.nsa.gov \
    --cc=sgrubb@redhat.com \
    --cc=torvalds@osdl.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome