Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: C2 certified OS that can run a firewall
From: peter @ baileynm . com (Peter da Silva)
Date: Mon, 9 Sep 1996 08:32:38 -0500 (CDT)
To: wombat @ mcfeely . bsfs . org (Rabid Wombat)
Cc: mcnabb @ argus . cu-online . com, firewalls @ GreatCircle . COM
In-reply-to: <Pine . BSF . 3 . 91 . 960906171849 . 319B-100000 @ mcfeely . bsfs . org> from "Rabid Wombat" at Sep 6, 96 05:56:22 pm

> Maybe. The biggest point for a "secure" OS vs. a "hardened" OS is that I 
> might want to be able to audit the actions of the person who has control 
> of the firewall system. This isn't a C2 thing, though, as I recall, but 
> comes up in the "B" rating. I could be wrong here, as I don't dig into 
> the rainbow books so much anymore.

That depends on how you interpret the book. DEC says no. Just about everyone
else (Secureware, Microsoft, etc) says yes, because of 2.2.2.2:

	"The TCB shall be able to record the following types of
	 events: [...] actions taken by computer operators and system
	 administrators and/or system security officers..."

What Microsoft and Secureware do is security by obscurity. They don't provide
documentation and tools necessary to allow you to dig into the TCB and fiddle
with it. Though I have found a way for Administrator to get read/write access
to the SAM without rebooting in NT. It's not any big secret, I've seen several
other people refer to it... it's like the old cron hole in UNIX many many
years ago.

> M$ used to ship NT with "everyone" having rights to the system directory. 
> This may still be the case, for all I know;

It is on NT 4.0 beta, and on 3.51. The resource kit has a tool that puts your
system into a C2 secure state, but lots of applications stop working and of
course networking is disabled.



Follow-Ups:
References:
Indexed By Date Previous: Network Security/Unix Network Security Conterence
From: meritj @ fincen . treas . gov (Jim Meritt)
Next: Re: curios traceroute
From: peter @ baileynm . com (Peter da Silva)
Indexed By Thread Previous: Re: C2 certified OS that can run a firewall
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>
Next: Re: C2 certified OS that can run a firewall
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>

Google
 
Search Internet Search www.greatcircle.com