mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Reiner Sailer <sailer@us.ibm.com>
To: James Morris <jmorris@redhat.com>
Cc: linux-kernel@vger.kernel.org, Andrew Morton <akpm@osdl.org>,
	Chris Wright <chrisw@osdl.org>,
	emilyr@us.ibm.com, yoder1@us.ibm.com,
	kjhall@us.ltcfwd.linux.ibm.com, linux-kernel@vger.kernel.org,
	toml@us.ibm.com
Subject: Re: [PATCH 1 of 4] ima: related TPM device driver interal kernel interface
Date: Fri, 20 May 2005 13:38:28 -0400 (Eastern Daylight Time)	[thread overview]
Message-ID: <Pine.WNT.4.63.0505201332400.4052@laptop> (raw)


James Morris <jmorris@redhat.com> wrote on 05/20/2005 10:56:20 AM:

> Why are you using LSM for this?
> 
> LSM should be used for comprehensive access control frameworks which 
> significantly enhance or even replace existing Unix DAC security.

I see LSM is framework for security. IMA is an architecture that
enforces access control in a different way than SELinux. IMA guarantees 
that executable content is measured and accounted for before
it is loaded and can access (and possibly corrupt) system resources.

> We're going to end up with a proliferation of arbitrary security 
features 
> lacking an overall architectural view (I've written about this before, 
> see http://www.ussg.iu.edu/hypermail/linux/kernel/0503.1/0300.html).
>
> I think it would be better to implement this directly.

The reason IMA is implemented as a Linux security module is that the LSM
interface allows the least intrusive implementation with regard to existing
kernel code. IMA is non-intrusive (its hooks return always nicely) and 
implements security guarantees that are orthogonal to those of, e.g., 
SELinux. Interactions with other LSM users are not expected. Experience 
shows that maintining IMA as LSM is simple.

There is no reason though why IMA must use LSM; however, it seems not the
straightforward solution to replicate LSM hooks that are already 
available.

> 
> - James
> -- 
> James Morris
> <jmorris@redhat.com>
> 
> 

Thanks
Reiner


             reply	other threads:[~2005-05-20 17:38 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-05-20 17:38 Reiner Sailer [this message]
  -- strict thread matches above, loose matches on Subject: below --
2005-05-20 20:41 Reiner Sailer
2005-05-21  5:57 ` Greg KH
     [not found] <OF78B8C5CF.5EB676A1-ON85257007.005EA7BF-85257007.005FF5F9@us.ibm.com>
2005-05-20 20:32 ` James Morris
2005-05-20 13:06 Kylene Hall
2005-05-20 14:56 ` James Morris

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Pine.WNT.4.63.0505201332400.4052@laptop \
    --to=sailer@us.ibm.com \
    --cc=akpm@osdl.org \
    --cc=chrisw@osdl.org \
    --cc=emilyr@us.ibm.com \
    --cc=jmorris@redhat.com \
    --cc=kjhall@us.ltcfwd.linux.ibm.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=toml@us.ibm.com \
    --cc=yoder1@us.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®