LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-24-2007, 09:11 AM   #1
slimm609
Member
 
Registered: May 2007
Location: Chas, SC
Distribution: slackware, gentoo, fedora, LFS, sidewinder G2, solaris, FreeBSD, RHEL, SUSE, Backtrack
Posts: 430

Rep: Reputation: 67
SELinux MLS


I wanted to find out if anyone has messed with the SELinux MLS policys or have used SELinux in a MLS environment. I know MLS is a who different side of selinux but i want to try and implement it along with a grsecurity protections and a few others. But if anyone has used MLS on linux and has any pointers please let me know.


Thanks
 
Old 08-25-2007, 06:08 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
No, I've never tried MLS as I'm still trying to reconcile myself with "targetted". As far as I know MLS would require you to build a policy from scratch for *everything* (though reasing http://fedoraproject.org/wiki/SELinux/FedoraMLSHowto it sounds kinda easy ;-p). BTW you can't have AND GRsecurity AND LSM in one running kernel, AFAIK they're incompatible.
 
Old 08-25-2007, 07:10 PM   #3
slimm609
Member
 
Registered: May 2007
Location: Chas, SC
Distribution: slackware, gentoo, fedora, LFS, sidewinder G2, solaris, FreeBSD, RHEL, SUSE, Backtrack
Posts: 430

Original Poster
Rep: Reputation: 67
you can run both on the same kernel at the same time but the issue is you can't have 2 access control methods. So i can run the kernel protection of grsecurity but the MAC of selinux. I just can't run gradm at all.

There are a few mls policies out there but I was not sure if anyone has messed with MLS
 
Old 08-26-2007, 05:36 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
i can run the kernel protection of grsecurity but the MAC of selinux. I just can't run gradm at all.
Thanks for the info. It triggered me to read up on things and apparently so it is possible.
 
Old 08-26-2007, 10:12 AM   #5
slimm609
Member
 
Registered: May 2007
Location: Chas, SC
Distribution: slackware, gentoo, fedora, LFS, sidewinder G2, solaris, FreeBSD, RHEL, SUSE, Backtrack
Posts: 430

Original Poster
Rep: Reputation: 67
I got bored so i started researching mls and somehow got the bright idea of hey why dont i try to build a trusted linux distro. and needless to say i am beating my head off the wall about MLS. I have the system almost build with grsecurity/selinux/ssp/pie/pic/hardened program patch then i get to start trying to do mls.
 
Old 08-26-2007, 10:24 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Gentoo (apparently the "easy" way for all the help and docs) or another dist?
 
Old 08-26-2007, 03:50 PM   #7
slimm609
Member
 
Registered: May 2007
Location: Chas, SC
Distribution: slackware, gentoo, fedora, LFS, sidewinder G2, solaris, FreeBSD, RHEL, SUSE, Backtrack
Posts: 430

Original Poster
Rep: Reputation: 67
i am creating my own trusted distro. I like using slackware as a base because of the installer being all bash. I dont have to worry about python or anything else. Just bash
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
"../system.h :selinux/selinux.h:no such file or directory" ashmita04 Linux From Scratch 4 02-05-2009 03:36 AM
LXer: Argus Systems Group Announces an MLS Linux Kernel LXer Syndicated Linux News 0 04-25-2006 06:03 PM
SELinux Vagrant Arch 3 02-24-2006 09:06 PM
what is selinux? mesh2005 Linux - General 2 01-04-2006 11:33 AM
SELinux winxshadi76 Linux - Newbie 1 12-03-2004 11:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:58 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration