Re: [Security-Discuss] tcb support under Mandriva
Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]> Mon, 28 Aug 2006 12:32:22 -0600
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Organization | Mandriva |
| Message-ID | <[email protected]> |
--HOIXJDerRg0rVrcW Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable * FACORAT Fabrice <[email protected]> [2006-08-28 19:35:31 +0200]: > > > IMHO you should, maybe for Corporate. > > > > Well, I'd like to think that I won't get ignored or discouraged, but > > since that tends to happen fairly often, I won't bother. I don't do the > > R&D, just support. With Annvix, on the other hand, I can do anything I > > bloody well feel like, which is why tcb support is in there. If nothing > > else, it demonstrates it could easily be done with Mandriva to boot. > > > > Chances are, if you bring it up, there's a higher probability someone > > will look at it more seriously than if I do (unfortunately, this is most > > probably true). >=20 > Ok, I will blog about this in my blog and also put it on cooker ML Sounds good. > > > Do you info about the evolution of RSBAC support ? they managed to do= a > > > tool ? they will no longer do it ? > > > > From what I understand, RSBAC is in the kernel, but is not enabled by > > default. You need to explicitly enable it with a kernel commandline (so > > an option in grub or lilo). Which means it won't be default (and also > > means 99.5% of the users won't use it, much less even know it's there). > > > > A tool? Not that I'm aware of. I've not seen or heard anything > > concrete about a tool actually being made available (and if you'll > > recall my blog entry, you'd need a helluvalot more than a single tool to > > make RSBAC something "convenient" to configure for joe-user). > > > > So, essentially, it's pretty much what I predicted. RSBAC will be in > > there, but no one will use it because we haven't made it easy to use. I > > won't start with how easy it would have been to switch to and use > > AppArmor instead.. my blog entry > > (http://linsec.ca/blog/index.php?/archives/81-RSBAC-and-AppArmor.html#e= xten > >ded for those interested) describes all the challenges, etc. >=20 > So your predictions were true :) Unfortunately, yes. > > FWIW, Mandriva's focus is not on proactive security. It never has been. > > It probably never will be (with the exception of MNF which was fairly > > well done from a security standpoint, although there is definitely room > > for improvement there too). The Corporate product line errs on the side > > of "what customers want" which ends up being lots of bloat, frivolous > > packages, and less security features than (I would like). That's not to > > say the Corporate products aren't good... they're great, if security > > isn't your primary concern. If lots of apps, hand-holding, and > > ease-of-use are your thing, they're great. Since (again, speaking about > > me personally) don't need lots of apps, don't like bloat, don't need my > > hand held (I'd rather whip out vim and edit some text config files), and > > have a primary focus on security, then I think you have two options: > > spend a fair amount of work cleaning and tightening Corp or find > > something else (Bastille might help in the former instance). >=20 > Unfortunately and we miss greatly management tools too. > My dream :=20 > - a wizard that allow to install OpenlDAP+NFSv4+kerberos > - a management tool to manage users, replication, rights ( web interface = ) +=20 > monitoring + share True, those wizards and tools would be fantastic. Of course, they could all be web-based (to prevent additional GUI bloat) instead of the traditional drak* tools (which are fine for Mandriva Linux, but add far too much unnecessary overhead in the Corp Server products). --=20 {FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4} mysql> SELECT * FROM users WHERE clue > 0; Empty set (0.00sec) --HOIXJDerRg0rVrcW Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (Darwin) iD8DBQFE8za2LrxeMv7jCtQRAh4hAKCkjkHbEYXU5cQKXznjgy4/80fkwACfZfZ1 6qr4HphIHjCLbjyhhKQKATY= =BKPm -----END PGP SIGNATURE----- --HOIXJDerRg0rVrcW--