Great Circle Associates Firewalls
(December 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Linux as a Firewall Platform
From: lists @ lina . inka . de (Bernd Eckenfels)
Date: Thu, 19 Dec 1996 03:24:58 +0100 (MET)
To: firewalls @ GreatCircle . com
In-reply-to: <9612181902 . AA17303 @ sonic . nmti . com . nmti . com> from "Peter da Silva" at Dec 18, 96 01:02:10 pm

Hi,

> Does it support the rest of the BSD securelevel stuff (for example, you can't
> access raw devices at high levels of security even as root)?

No not yet. This is partially because it won't be necessary with Mandatory
Acess control and Posix Priveleges. Ted was working on that. But it is
fairly easy to protect raw devices writes, module loading and other stuff by
a bit of securelevel. AFAIK you can make the raw devices immutable...

Greetings
Bernd


Follow-Ups:
References:
Indexed By Date Previous: RADIUS PARAMETERS
From: Jose Antonio Izquierdo <jail97 @ medusa . es>
Next: Re: smap delays
From: Rick Murphy <rick @ tis . com>
Indexed By Thread Previous: Re: Linux as a Firewall Platform
From: peter @ baileynm . com (Peter da Silva)
Next: Re: Linux as a Firewall Platform
From: Ambrose Li <news-misc @ byron . net4 . io . org>

Google
 
Search Internet Search www.greatcircle.com