[Apparmor-dev] Re: AppArmor Security Goal
Casey Schaufler
casey at schaufler-ca.com
Sat Nov 10 19:17:30 MST 2007
--- Crispin Cowan <crispin at crispincowan.com> wrote:
> Dr. David Alan Gilbert wrote:
> ...
>
> Can you explain why you want a non-privileged user to be able to edit
> policy? I would like to better understand the problem here.
>
> Note that John Johansen is also interested in allowing non-privileged
> users to manipulate AppArmor policy, but his view was to only allow a
> non-privileged user to further tighten the profile on a program. To me,
> that adds complexity with not much value, but if lots of users want it,
> then I'm wrong :)
Now this is getting interesting. It looks to me as if you've implemented
a mandatory access control scheme that some people would like to be able
to use as a discretionary access control scheme. This is creepy after
seeing the MCS implementation in SELinux, which is also a DAC scheme
wacked out of a MAC scheme. Very interesting indeed.
Casey Schaufler
casey at schaufler-ca.com
More information about the Apparmor-dev
mailing list