Re: Slides
"Jonathan S. Shapiro" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAAP=3QNpJhRmK_NWyoFK=Xhako4_BA6+NX1YCPRN0y+3Nx8gdw@mail.gmail.com> |
On Mon, Aug 5, 2013 at 1:45 AM, Ben Laurie <[email protected]> wrote: > On 4 August 2013 21:53, Jonathan S. Shapiro <[email protected]> wrote: > >> AppArmor should probably be seen as a reaction to SELinux, which is far >> too complicated to be useful in practice. I actually *do* know how >> SELinux works, and I've build SELinux profiles (or whatever the hell they >> are called), and it's *awful*. For most people, you can forget it. >> That's why most people run with SELinux disabled on systems that support it. >> > > I thought AppArmor was built in parallel to SELinux, so not really a > reaction? > You're probably right. Crispin was one of the earliest "inside" proponents of LSM, and AppArmor was originally crafted to support Immunix. It's sometimes hard to say what happens in what order in these matters. Crispin and I both had regular contact with the SELinux team at NSA well before it was called SELinux. We were aware of their efforts to put MAC support into Linux, and both of us (for very different reasons) felt they were on the wrong path at the time. shap _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk