Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support

From: James Morris
Date: Tue Mar 13 2018 - 17:52:26 EST


On Tue, 13 Mar 2018, Stefan Berger wrote:

> On 03/11/2018 06:58 PM, James Morris wrote:
> > On Fri, 9 Mar 2018, Stefan Berger wrote:
> >
> > > Yuqiong is publishing a paper in this area. I believe the conference is
> > > only
> > > later this year.
> > >
> > > Our goals are to enable IMA measurements, appraisal, and auditing inside a
> > > container using namespaces.
> > This is excellent to have -- can you include this requirements analysis as
> > a file Documentation/security on the next posting?
> >
> > Also, if you need a public space for managing these kinds of documents,
> > consider utilizing
> > http://kernsec.org/wiki/index.php/Linux_Kernel_Integrity
>
> Thanks for the pointer. I tried creating an account, but the interface
> wouldn't let me. Who is managing it?

Email me for an account, per the note on the front page.


--
James Morris
<jmorris@xxxxxxxxx>