From mboxrd@z Thu Jan 1 00:00:00 1970 From: James Morris Subject: Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support Date: Mon, 12 Mar 2018 09:58:02 +1100 (AEDT) Message-ID: References: <20170720225033.21298-1-mkayaalp@linux.vnet.ibm.com> <20170720225033.21298-2-mkayaalp@linux.vnet.ibm.com> <20170725175317.GA727@mail.hallyn.com> <1501008554.3689.30.camel@HansenPartnership.com> <20170725190406.GA1883@mail.hallyn.com> <1501009739.3689.33.camel@HansenPartnership.com> <1501012082.27413.17.camel@linux.vnet.ibm.com> <645db815-7773-e351-5db7-89f38cd88c3d@linux.vnet.ibm.com> <20170725204622.GA4969@mail.hallyn.com> <97839865-b0ab-8e5d-114e-0603ef2edf6f@linux.vnet.ibm.com> <20180309025942.GA15295@mail.hallyn.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org Errors-To: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org To: Stefan Berger Cc: Mehmet Kayaalp , Mehmet Kayaalp , Yuqiong Sun , containers , linux-kernel , David Safford , James Bottomley , linux-security-module , ima-devel , Yuqiong Sun , Mimi Zohar List-Id: containers.vger.kernel.org On Fri, 9 Mar 2018, Stefan Berger wrote: > Yuqiong is publishing a paper in this area. I believe the conference is only > later this year. > > Our goals are to enable IMA measurements, appraisal, and auditing inside a > container using namespaces. This is excellent to have -- can you include this requirements analysis as a file Documentation/security on the next posting? Also, if you need a public space for managing these kinds of documents, consider utilizing http://kernsec.org/wiki/index.php/Linux_Kernel_Integrity - James -- James Morris