Re: [Security-Discuss] tcb support under Mandriva
Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]> Fri, 25 Aug 2006 12:36:27 -0600
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Organization | Mandriva |
| Message-ID | <[email protected]> |
--qrxaW5QmeXhOrNsF Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable * FACORAT Fabrice <[email protected]> [2006-08-25 19:17:48 +0200]: > > > http://www.builderau.com.au/program/linux/soa/Migrating_from_shadow_p= assw > > >ords_to_tcb_in_Linux/0,39028297,39269540,00.htm > > > > > > I've read your article about tcb support under Linux and I'm willing = to > > > know if the needed patch have been integrated in the required tools in > > > Mandriva ? > > > > Nope. > > > > It shouldn't be too hard to integrate it tho. I don't know if Mandriva > > has any interest in it, and it's a little late in the game to get it in > > there for 2007 I think. It would require patching glibc (to get > > blowfish support, which we should do anyways) and a few userland tools > > (mostly shadow-utils I think). And the proper rpms (which can be taken > > from Annvix and modified for use with Mandriva... should take all of 5 > > minutes). > > > > There would be some distinct advantages (tcb over shadow rocks), but > > normally my ideas are shot down so I haven't even bothered proposing it. >=20 > IMHO you should, maybe for Corporate. Well, I'd like to think that I won't get ignored or discouraged, but since that tends to happen fairly often, I won't bother. I don't do the R&D, just support. With Annvix, on the other hand, I can do anything I bloody well feel like, which is why tcb support is in there. If nothing else, it demonstrates it could easily be done with Mandriva to boot. Chances are, if you bring it up, there's a higher probability someone will look at it more seriously than if I do (unfortunately, this is most probably true). > Do you info about the evolution of RSBAC support ? they managed to do a t= ool ?=20 > they will no longer do it ? =46rom what I understand, RSBAC is in the kernel, but is not enabled by default. You need to explicitly enable it with a kernel commandline (so an option in grub or lilo). Which means it won't be default (and also means 99.5% of the users won't use it, much less even know it's there). A tool? Not that I'm aware of. I've not seen or heard anything concrete about a tool actually being made available (and if you'll recall my blog entry, you'd need a helluvalot more than a single tool to make RSBAC something "convenient" to configure for joe-user). So, essentially, it's pretty much what I predicted. RSBAC will be in there, but no one will use it because we haven't made it easy to use. I won't start with how easy it would have been to switch to and use AppArmor instead.. my blog entry (http://linsec.ca/blog/index.php?/archives/81-RSBAC-and-AppArmor.html#exten= ded for those interested) describes all the challenges, etc. FWIW, Mandriva's focus is not on proactive security. It never has been. It probably never will be (with the exception of MNF which was fairly well done from a security standpoint, although there is definitely room for improvement there too). The Corporate product line errs on the side of "what customers want" which ends up being lots of bloat, frivolous packages, and less security features than (I would like). That's not to say the Corporate products aren't good... they're great, if security isn't your primary concern. If lots of apps, hand-holding, and ease-of-use are your thing, they're great. Since (again, speaking about me personally) don't need lots of apps, don't like bloat, don't need my hand held (I'd rather whip out vim and edit some text config files), and have a primary focus on security, then I think you have two options: spend a fair amount of work cleaning and tightening Corp or find something else (Bastille might help in the former instance). I'd like to rant more, but I think I'm getting myself into trouble already. =3D) The last thing I'll say is that Corp isn't my style for servers, but my style isn't the "average user" style either. My style is a lot more spartan, a lot more manual, and (I think) a lot more flexible. Which is why I've got my little side-hobby project where I can do what I want without worrying about what other people want or think. It suits my style (truth be told, there's no other distro out there that suits my style anyways... I'd pick Corp over anything else out there today be it Fedora, SUSE, Debian, etc.). Ok, I've said enough now.. =3D) --=20 {FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4} mysql> SELECT * FROM users WHERE clue > 0; Empty set (0.00sec) --qrxaW5QmeXhOrNsF Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (Darwin) iD8DBQFE70MqLrxeMv7jCtQRAsWnAKCiwD5SXwWfpuIHPIwsMxWinCBzaQCgwdv9 0Bgkv9FNDPl/HFF+S9FQOgc= =gtRU -----END PGP SIGNATURE----- --qrxaW5QmeXhOrNsF--