|
Firewalls (December 1996) |
Hi, > Does it support the rest of the BSD securelevel stuff (for example, you can't > access raw devices at high levels of security even as root)? No not yet. This is partially because it won't be necessary with Mandatory Acess control and Posix Priveleges. Ted was working on that. But it is fairly easy to protect raw devices writes, module loading and other stuff by a bit of securelevel. AFAIK you can make the raw devices immutable... Greetings Bernd Follow-Ups:
References:
|