mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Reiner Sailer <sailer@us.ibm.com>
To: Chris Wright <chrisw@osdl.org>
Cc: serue@us.ibm.com, James Morris <jmorris@redhat.com>,
	Reiner Sailer <sailer@watson.ibm.com>,
	LKML <linux-kernel@vger.kernel.org>,
	LSM <linux-security-module@wirex.com>,
	Toml@us.ibm.com, Greg KH <greg@kroah.com>,
	Emilyr@us.ibm.com, kylene@us.ibm.com
Subject: Re: [PATCH] 3 of 5 IMA: LSM-based measurement code
Date: Wed, 15 Jun 2005 18:44:22 -0400 (Eastern Daylight Time)	[thread overview]
Message-ID: <Pine.WNT.4.63.0506151754150.2452@laptop> (raw)


Chris Wright <chrisw@osdl.org> wrote on 06/15/2005 05:53:01 PM:

> * serue@us.ibm.com (serue@us.ibm.com) wrote:
> > Quoting Chris Wright (chrisw@osdl.org):
> > > The primary purpose of the hooks is access control.  Some of them, of
> > > course, are helpers to keep labels coherent.  IIRC, James objected
> > > because the measurement data was simply collected from these hooks.
> > 
> > Ok, so to be clear, any module which does not directly impose some form
> > of access control is not eligible for an LSM?
> 
> That's exactly the intention, yes.

Chris,

Access control is a very broad term. Before I go into details, I would 
like to make clear that I do not have a preference for or against LSM. We 
are working hard to make the functionality available and it does not 
matter to the user where IMA will be located. The true potential of 
Trusted Computing will only show with experimenting going on outside 
the research labs. IMA can help by being one modest building block 
for experiments only if it is broadly available.

Regarding the access control discussion, one can map (almost) anything 
onto access control. There are (many) people that teach today that the 
whole security issue is about access control. The question is: 
controlling access of whom to what?

IMA does control access by forcing measurements on executables
before they are loaded. Access control is more than saying yes or no at 
some point on the code path. IMA enables remote parties to figure out 
whether a system has some (usage dependent) properties. This can serve as 
the basis for controlling such systems' access to resources. IMA supplies 
input into a remote Access Control Decision Function.

These properties neither justify IMA to be excluded as LSM, nor force IMA 
to be an LSM.


> thanks,
> -chris

Thanks 
Reiner


             reply	other threads:[~2005-06-15 22:45 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-06-15 22:44 Reiner Sailer [this message]
2005-06-15 22:59 ` Chris Wright
  -- strict thread matches above, loose matches on Subject: below --
2005-06-15 22:48 Reiner Sailer
2005-06-15 14:40 Reiner Sailer
2005-06-15 20:02 ` James Morris
2005-06-15 20:49   ` serue
2005-06-15 20:58     ` Stephen Smalley
2005-06-15 21:48       ` serue
2005-06-15 20:59     ` Chris Wright
2005-06-15 21:50       ` serue
2005-06-15 21:53         ` Chris Wright
2005-06-15 22:42           ` Serge E. Hallyn
2005-06-15 22:49             ` Chris Wright
2005-06-15 22:00         ` Casey Schaufler
2005-06-15 22:38           ` Serge E. Hallyn
2005-06-15 22:40             ` Chris Wright
2005-06-15 22:52               ` Serge E. Hallyn
2005-06-16  2:01 ` Chris Wright

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Pine.WNT.4.63.0506151754150.2452@laptop \
    --to=sailer@us.ibm.com \
    --cc=Emilyr@us.ibm.com \
    --cc=Toml@us.ibm.com \
    --cc=chrisw@osdl.org \
    --cc=greg@kroah.com \
    --cc=jmorris@redhat.com \
    --cc=kylene@us.ibm.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@wirex.com \
    --cc=sailer@watson.ibm.com \
    --cc=serue@us.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®