archive mirror
 help / color / mirror / Atom feed
* Possible user base and mainline inclusion of LSM-based security improvements.
@ 2005-01-09 19:42 Lorenzo Hernández García-Hierro
  0 siblings, 0 replies; only message in thread
From: Lorenzo Hernández García-Hierro @ 2005-01-09 19:42 UTC (permalink / raw)
  To: linux-kernel, linux-security-module; +Cc: alan

[-- Attachment #1: Type: text/plain, Size: 1925 bytes --]


I'm now writing a "safe networking" LSM, inspired by grSecurity socket
restriction capabilities.

Currently, it provides users and groups (uid and gid based) Access
Control Lists, which can be changed in runtime by a new interface based
on my other LSM, the TPE, which registers a subsystem in sysfs and
creates  the needed entries for "realtime" configuration under secfs in
the mountpoint of sysfs (normally /sys/).

I'ts intended to provide a base of enhanced features inspired by the
well-designed grSecurity patch maintained and developed by Brad Spengler
(a.k.a. spender), by now i have the TPE and this LSM almost done.

The main goal is to provide an also well-designed (as most as possible)
security improvement using the LSM framework for Vanilla sources.

The main problem is that people often needs security enhancements that
they can not get by using the default Vanilla sources, even in an easy,
"user friendly" way.

What's more simple than insmod'ding a module?

Maybe the LSM framework is not the best one, or it's just not reliable
for this as some people and colectives said before, but i want to give
it a chance, even if this work could be nonsense for some people, it's
also for my own fun and coding profit.

If someone wants to help with this idea (i can not call it a project but
seems going to be :) ), just tell me.

Also, i would appreciate knowing the opinion from both kernel hackers
and users "vocal" base, about the inclusion of this security
improvements in the main line.

Tomorrow, my school time will start again after these Christmas
holidays, so, i will have more limited time and less nights (umm, none
maybe) to work on this stuff, until i get spin_unlock()'ed again ;).

Thanks in advance, cheers.
Lorenzo Hernández García-Hierro <> [1024D/6F2B2DEC]
[2048g/9AE91A22] Hardened Debian head developer & project manager

[-- Attachment #2: Esta parte del mensaje está firmada digitalmente --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2005-01-09 19:44 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2005-01-09 19:42 Possible user base and mainline inclusion of LSM-based security improvements Lorenzo Hernández García-Hierro

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).