Re: [Security-Discuss] tcb support under Mandriva

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]> Fri, 25 Aug 2006 12:36:27 -0600
Newsgroups gmane.linux.mandrake.security.general
Organization Mandriva
Message-ID <[email protected]>
--qrxaW5QmeXhOrNsF
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

* FACORAT Fabrice <[email protected]> [2006-08-25 19:17:48 +0200]:

> > > http://www.builderau.com.au/program/linux/soa/Migrating_from_shadow_p=
assw
> > >ords_to_tcb_in_Linux/0,39028297,39269540,00.htm
> > >
> > > I've read your article about tcb support under Linux and I'm willing =
to
> > > know if the needed patch have been integrated in the required tools in
> > > Mandriva ?
> >
> > Nope.
> >
> > It shouldn't be too hard to integrate it tho.  I don't know if Mandriva
> > has any interest in it, and it's a little late in the game to get it in
> > there for 2007 I think.  It would require patching glibc (to get
> > blowfish support, which we should do anyways) and a few userland tools
> > (mostly shadow-utils I think).  And the proper rpms (which can be taken
> > from Annvix and modified for use with Mandriva... should take all of 5
> > minutes).
> >
> > There would be some distinct advantages (tcb over shadow rocks), but
> > normally my ideas are shot down so I haven't even bothered proposing it.
>=20
> IMHO you should, maybe for Corporate.

Well, I'd like to think that I won't get ignored or discouraged, but
since that tends to happen fairly often, I won't bother.  I don't do the
R&D, just support.  With Annvix, on the other hand, I can do anything I
bloody well feel like, which is why tcb support is in there.  If nothing
else, it demonstrates it could easily be done with Mandriva to boot.

Chances are, if you bring it up, there's a higher probability someone
will look at it more seriously than if I do (unfortunately, this is most
probably true).

> Do you info about the evolution of RSBAC support ? they managed to do a t=
ool ?=20
> they will no longer do it ?

=46rom what I understand, RSBAC is in the kernel, but is not enabled by
default.  You need to explicitly enable it with a kernel commandline (so
an option in grub or lilo).  Which means it won't be default (and also
means 99.5% of the users won't use it, much less even know it's there).

A tool?  Not that I'm aware of.  I've not seen or heard anything
concrete about a tool actually being made available (and if you'll
recall my blog entry, you'd need a helluvalot more than a single tool to
make RSBAC something "convenient" to configure for joe-user).

So, essentially, it's pretty much what I predicted.  RSBAC will be in
there, but no one will use it because we haven't made it easy to use.  I
won't start with how easy it would have been to switch to and use
AppArmor instead.. my blog entry
(http://linsec.ca/blog/index.php?/archives/81-RSBAC-and-AppArmor.html#exten=
ded
for those interested) describes all the challenges, etc.

FWIW, Mandriva's focus is not on proactive security.  It never has been.
It probably never will be (with the exception of MNF which was fairly
well done from a security standpoint, although there is definitely room
for improvement there too).  The Corporate product line errs on the side
of "what customers want" which ends up being lots of bloat, frivolous
packages, and less security features than (I would like).  That's not to
say the Corporate products aren't good... they're great, if security
isn't your primary concern.  If lots of apps, hand-holding, and
ease-of-use are your thing, they're great.  Since (again, speaking about
me personally) don't need lots of apps, don't like bloat, don't need my
hand held (I'd rather whip out vim and edit some text config files), and
have a primary focus on security, then I think you have two options:
spend a fair amount of work cleaning and tightening Corp or find
something else (Bastille might help in the former instance).

I'd like to rant more, but I think I'm getting myself into trouble
already.  =3D)  The last thing I'll say is that Corp isn't my style for
servers, but my style isn't the "average user" style either.  My style
is a lot more spartan, a lot more manual, and (I think) a lot more
flexible.  Which is why I've got my little side-hobby project where I
can do what I want without worrying about what other people want or
think.  It suits my style (truth be told, there's no other distro out
there that suits my style anyways... I'd pick Corp over anything else
out there today be it Fedora, SUSE, Debian, etc.).

Ok, I've said enough now.. =3D)

--=20
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
mysql> SELECT * FROM users WHERE clue > 0;
Empty set (0.00sec)

--qrxaW5QmeXhOrNsF
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (Darwin)

iD8DBQFE70MqLrxeMv7jCtQRAsWnAKCiwD5SXwWfpuIHPIwsMxWinCBzaQCgwdv9
0Bgkv9FNDPl/HFF+S9FQOgc=
=gtRU
-----END PGP SIGNATURE-----

--qrxaW5QmeXhOrNsF--