From: Reiner Sailer <sailer@us.ibm.com>
To: James Morris <jmorris@redhat.com>
Cc: linux-kernel@vger.kernel.org, Andrew Morton <akpm@osdl.org>,
Chris Wright <chrisw@osdl.org>,
emilyr@us.ibm.com, yoder1@us.ibm.com,
kjhall@us.ltcfwd.linux.ibm.com, linux-kernel@vger.kernel.org,
toml@us.ibm.com
Subject: Re: [PATCH 1 of 4] ima: related TPM device driver interal kernel interface
Date: Fri, 20 May 2005 13:38:28 -0400 (Eastern Daylight Time) [thread overview]
Message-ID: <Pine.WNT.4.63.0505201332400.4052@laptop> (raw)
James Morris <jmorris@redhat.com> wrote on 05/20/2005 10:56:20 AM:
> Why are you using LSM for this?
>
> LSM should be used for comprehensive access control frameworks which
> significantly enhance or even replace existing Unix DAC security.
I see LSM is framework for security. IMA is an architecture that
enforces access control in a different way than SELinux. IMA guarantees
that executable content is measured and accounted for before
it is loaded and can access (and possibly corrupt) system resources.
> We're going to end up with a proliferation of arbitrary security
features
> lacking an overall architectural view (I've written about this before,
> see http://www.ussg.iu.edu/hypermail/linux/kernel/0503.1/0300.html).
>
> I think it would be better to implement this directly.
The reason IMA is implemented as a Linux security module is that the LSM
interface allows the least intrusive implementation with regard to existing
kernel code. IMA is non-intrusive (its hooks return always nicely) and
implements security guarantees that are orthogonal to those of, e.g.,
SELinux. Interactions with other LSM users are not expected. Experience
shows that maintining IMA as LSM is simple.
There is no reason though why IMA must use LSM; however, it seems not the
straightforward solution to replicate LSM hooks that are already
available.
>
> - James
> --
> James Morris
> <jmorris@redhat.com>
>
>
Thanks
Reiner
next reply other threads:[~2005-05-20 17:38 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-05-20 17:38 Reiner Sailer [this message]
-- strict thread matches above, loose matches on Subject: below --
2005-05-20 20:41 Reiner Sailer
2005-05-21 5:57 ` Greg KH
[not found] <OF78B8C5CF.5EB676A1-ON85257007.005EA7BF-85257007.005FF5F9@us.ibm.com>
2005-05-20 20:32 ` James Morris
2005-05-20 13:06 Kylene Hall
2005-05-20 14:56 ` James Morris
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Pine.WNT.4.63.0505201332400.4052@laptop \
--to=sailer@us.ibm.com \
--cc=akpm@osdl.org \
--cc=chrisw@osdl.org \
--cc=emilyr@us.ibm.com \
--cc=jmorris@redhat.com \
--cc=kjhall@us.ltcfwd.linux.ibm.com \
--cc=linux-kernel@vger.kernel.org \
--cc=toml@us.ibm.com \
--cc=yoder1@us.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®