--- Stephen Smalley <[EMAIL PROTECTED]> wrote:

> To the contrary, the LSPP work significantly
> leverages the work already
> done to integrate SELinux and makes use of the
> SELinux interfaces for
> applications.  It also leverages SELinux TE to
> address aspects such as
> MLS overrides.  By doing it within the context of
> SELinux, it gained the
> benefit of a unified security model and interface. 
> Which one doesn't get from LSM.

There are others who would argue that SELinux
has abandoned the Linux privilege model and
thus disrupted the unity of the existing
security model.

I don't understand why the SELinux crew seems
so intent on making it difficult to implement
alternatives. Last year it was "let's ditch LSM".
Now it's "Everyone hates stacking". Give it a
rest already.


Casey Schaufler
[EMAIL PROTECTED]
-
To unsubscribe from this list: send the line "unsubscribe 
linux-security-module" in
the body of a message to [EMAIL PROTECTED]
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Reply via email to