You could also just have a config file like /etc/auditopen containing the capability list of the binaries.
What is wrong with that?
> Other topics that came up:
>
> 1. what is a suitable list of capabilities?
You could say that the max list of capabilities is the complete list of sys_calls.
> 2. What granularity is supported by the capabilities?
What do you mean?
> 3. Can site defined capabilities be defined?
> 4. (related to 3) Can application specific capabilities be defined?
You could think of extending the configfile from a binary specific to a binary and process specific. But as far as I can see binary specific will to enough. Could you give me an example where binary specific configfiles are not enough?
>
> See the RSBAC project at http://www.rsbac.de/rsbac/
> for an implementation of MAC controls, including compartmented operation.
> -------------------------------------------------------------------------
> Jesse I Pollard, II
> Email: pollard@navo.hpc.mil
>
> Any opinions expressed are solely my own.
>
> -
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to majordomo@vger.rutgers.edu
> Please read the FAQ at http://www.tux.org/lkml/
Frank van Vliet
karin@root66.org
RooT66 - http://root66.org
ShellOracle - http://www.shelloracle.cjb.com
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/