Re: [RFC] LSM changes for 2.5.38

Valdis.Kletnieks@vt.edu
Fri, 27 Sep 2002 14:09:02 -0400


--==_Exmh_-1145979100P
Content-Type: text/plain; charset=us-ascii

On Fri, 27 Sep 2002 17:55:10 BST, Christoph Hellwig said:

> And WTF is the use a security policy that checks module arguments? Do
> you want to disallow options that are quotes from books on the index
> or not political correct enough for a US state agency?

How about a security policy that says:

1) Thou mayest do an 'modprobe wvlan_cs'

2) Thou mayest not do 'modprobe wvlan_cs eth=0'.

'eth=0' causes it to create the interface as 'wvlan0' 'wvlan1' etc rather
than 'eth0', 'eth1', etc. This makes a difference if you have iptables
rules that say '-i eth+' or '-i wvlan+' that implement different rulesets
for wireless and hard-wired connections.

-- 
				Valdis Kletnieks
				Computer Systems Senior Engineer
				Virginia Tech

--==_Exmh_-1145979100P Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) Comment: Exmh version 2.5 07/13/2001

iD8DBQE9lJ6+cC3lWbTT17ARAnL4AJ9Ki7Let8JvTDDw0V320JpqeCmTrQCgzYOd rz8xa+xWV+8+8MHZrG8wqZ8= =Vp0O -----END PGP SIGNATURE-----

--==_Exmh_-1145979100P-- - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/