Re: [Security-Discuss] tcb support under Mandriva

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]> Mon, 28 Aug 2006 12:32:22 -0600
Newsgroups gmane.linux.mandrake.security.general
Organization Mandriva
Message-ID <[email protected]>
--HOIXJDerRg0rVrcW
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

* FACORAT Fabrice <[email protected]> [2006-08-28 19:35:31 +0200]:

> > > IMHO you should, maybe for Corporate.
> >
> > Well, I'd like to think that I won't get ignored or discouraged, but
> > since that tends to happen fairly often, I won't bother.  I don't do the
> > R&D, just support.  With Annvix, on the other hand, I can do anything I
> > bloody well feel like, which is why tcb support is in there.  If nothing
> > else, it demonstrates it could easily be done with Mandriva to boot.
> >
> > Chances are, if you bring it up, there's a higher probability someone
> > will look at it more seriously than if I do (unfortunately, this is most
> > probably true).
>=20
> Ok, I will blog about this in my blog and also put it on cooker ML

Sounds good.

> > > Do you info about the evolution of RSBAC support ? they managed to do=
 a
> > > tool ? they will no longer do it ?
> >
> > From what I understand, RSBAC is in the kernel, but is not enabled by
> > default.  You need to explicitly enable it with a kernel commandline (so
> > an option in grub or lilo).  Which means it won't be default (and also
> > means 99.5% of the users won't use it, much less even know it's there).
> >
> > A tool?  Not that I'm aware of.  I've not seen or heard anything
> > concrete about a tool actually being made available (and if you'll
> > recall my blog entry, you'd need a helluvalot more than a single tool to
> > make RSBAC something "convenient" to configure for joe-user).
> >
> > So, essentially, it's pretty much what I predicted.  RSBAC will be in
> > there, but no one will use it because we haven't made it easy to use.  I
> > won't start with how easy it would have been to switch to and use
> > AppArmor instead.. my blog entry
> > (http://linsec.ca/blog/index.php?/archives/81-RSBAC-and-AppArmor.html#e=
xten
> >ded for those interested) describes all the challenges, etc.
>=20
> So your predictions were true :)

Unfortunately, yes.

> > FWIW, Mandriva's focus is not on proactive security.  It never has been.
> > It probably never will be (with the exception of MNF which was fairly
> > well done from a security standpoint, although there is definitely room
> > for improvement there too).  The Corporate product line errs on the side
> > of "what customers want" which ends up being lots of bloat, frivolous
> > packages, and less security features than (I would like).  That's not to
> > say the Corporate products aren't good... they're great, if security
> > isn't your primary concern.  If lots of apps, hand-holding, and
> > ease-of-use are your thing, they're great.  Since (again, speaking about
> > me personally) don't need lots of apps, don't like bloat, don't need my
> > hand held (I'd rather whip out vim and edit some text config files), and
> > have a primary focus on security, then I think you have two options:
> > spend a fair amount of work cleaning and tightening Corp or find
> > something else (Bastille might help in the former instance).
>=20
> Unfortunately and we miss greatly management tools too.
> My dream :=20
> - a wizard that allow to install OpenlDAP+NFSv4+kerberos
> - a management tool to manage users, replication, rights ( web interface =
) +=20
> monitoring + share

True, those wizards and tools would be fantastic.  Of course, they could
all be web-based (to prevent additional GUI bloat) instead of the
traditional drak* tools (which are fine for Mandriva Linux, but add far
too much unnecessary overhead in the Corp Server products).

--=20
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
mysql> SELECT * FROM users WHERE clue > 0;
Empty set (0.00sec)

--HOIXJDerRg0rVrcW
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (Darwin)

iD8DBQFE8za2LrxeMv7jCtQRAh4hAKCkjkHbEYXU5cQKXznjgy4/80fkwACfZfZ1
6qr4HphIHjCLbjyhhKQKATY=
=BKPm
-----END PGP SIGNATURE-----

--HOIXJDerRg0rVrcW--