LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-17-2015, 02:25 AM   #1
amoya
LQ Newbie
 
Registered: Apr 2015
Posts: 2

Rep: Reputation: Disabled
How to implement and configure MLS (BLP model) in SELinux?


I'm currently studying about bell-lapadula model for my research and I need to implementation it as a simple example. I want to implement a simple BLP model using SELinux on my virtual machine Centos. In my research, I have 4 user, which represent four levels of security (Top Secret, Secret, Unclassified, Public) and each user has their own folder. I just want to know how to enable MLS in SELinux, set the BLP rules in SELinux?

Before, I use this reference https://access.redhat.com/documentat...n-selinux.html. But in the last step, I always failed to access root, maybe you can help me.. or you have a specific reference to me learn it? Just a simple example maybe? Thx
 
Old 04-17-2015, 06:14 AM   #2
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
Not certain of this... But I don't think a pure BLP even has a root. The two systems I had access to (both were the old Cray Y systems) with a BLP foundation had extensions to allow for a root.

BTW, which version CentOS are you using?
 
Old 04-17-2015, 06:28 AM   #3
amoya
LQ Newbie
 
Registered: Apr 2015
Posts: 2

Original Poster
Rep: Reputation: Disabled
Thank you for your help. I'm using centOS version 6.6

Last edited by amoya; 04-17-2015 at 06:31 AM.
 
Old 04-18-2015, 11:13 AM   #4
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
I'm not sure the BLP implemented is actually usable. There are a LOT of difficult areas, and I'm not certain they have been addressed. I don't believe anyone actually uses it.

1. X can't be used (not BLP aware)
2. without IPsec, network connections can't be labelled either.
3. Administration must (in a pure environment) be done before the system is booted - which means all configurations have to be set with SELinux disabled (or in permissive mode).

I think it was created more to show that the SELinux model(flask) could be used to define a BLP operation, thus showing the flask foundation was more powerful.

Last edited by jpollard; 04-18-2015 at 11:15 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
configure linux rdp v6 model in wyse s50 joricardoo Linux - Newbie 0 02-03-2012 12:21 PM
SELinux MLS messing me up? jnojr Linux - Security 2 01-27-2009 02:49 PM
how to implement MLS policies? gaurav gupta Linux - Security 2 09-25-2007 11:24 PM
SELinux MLS slimm609 Linux - Security 6 08-26-2007 03:50 PM
LXer: Implement a relaxed immutability model in Java LXer Syndicated Linux News 0 02-27-2007 08:01 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration