selinux.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Security labeling in NFS4 - who owns it?
@ 2019-08-01 19:39 Casey Schaufler
  2019-08-01 22:02 ` Paul Moore
  0 siblings, 1 reply; 3+ messages in thread
From: Casey Schaufler @ 2019-08-01 19:39 UTC (permalink / raw)
  To: linux-nfs, Linux Security Module list, SELinux, Trond Myklebust,
	Anna Schumaker
  Cc: casey

As part of my work on LSM stacking I've encountered some issues with
the Linux implementation of NFS4 security labels. For example, the LFS
data is ignored, so even if the client and server are willing to identify
the kind of information they are passing, the identity information isn't
available. The code asks if attributes requested are mandatory access
control attributes, but cannot differentiate between which of the possible
security attribute the other end is providing.

Is anyone actively owing the NFS labeling code? I'd like to bounce an
idea or two around before committing too much time to my ideas of
solutions.

 



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2019-08-01 22:47 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-08-01 19:39 Security labeling in NFS4 - who owns it? Casey Schaufler
2019-08-01 22:02 ` Paul Moore
2019-08-01 22:47   ` Casey Schaufler

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).