Re: Time to remove LSM (was Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks)

From: Serge E. Hallyn
Date: Mon Apr 24 2006 - 10:28:20 EST


Quoting Alan Cox (alan@xxxxxxxxxxxxxxxxxxx):
> On Llu, 2006-04-24 at 09:04 -0500, Serge E. Hallyn wrote:
> > Quoting Alan Cox (alan@xxxxxxxxxxxxxxxxxxx):
> > > Thus this sort of stuff needs to be taken seriously. Can SuSE provide a
> > > good reliable policy for AppArmour to people, can Red Hat do the same
> > > with SELinux ?
> >
> > That's a little more than half the question. The other 40% is can users
> > write good policies.
>
> Normal users don't write file system allocation policies, they don't
> configure the safety systems for their car and they don't generally
> configure most other similar policies.

s/users/everyday admin/ ?

Perhaps in the end a massive amount of education is the only answer.
But in any case only good can come of such a contest.

-serge
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/