--- Tom Fortmann <[EMAIL PROTECTED]> wrote:

> Are their any current or future plans to support
> stacking additional
> security modules on the LSM interface?

It has certainly been considered from
time to time. David Wheeler's early work
came pretty close.

> Alternatively, are there any current or future plans
> to allow the SELinux
> framework to be expanded with third party loadable
> modules?

SELinux does currently, although somewhat
begrudgingly, allow limited stacking in
support of a particular set of modules. 

It wasn't but a year ago that the SELinux
community was arguing that LSM ought to be
dispensed with, as they argued that:
  - No one else was using LSM
  - SELinux does everything that a rational
    being might want done anyway.

> We are working on some enhanced security solutions
> that require access to
> the LSM interface, but we do not want to preclude
> the use of SELinux by our
> customers.

You might take this onto the LSM list (I've
added it to the CC here) as there are a (very)
few people who follow LSM that do not subscribe
here.

Just out of curiosity, what's your module
going to do?


Casey Schaufler
[EMAIL PROTECTED]
-
To unsubscribe from this list: send the line "unsubscribe 
linux-security-module" in
the body of a message to [EMAIL PROTECTED]
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Reply via email to