Re: [PATCH] selinux: include a consumer of the new IMA critical data hook

2021-01-24 Thread Mimi Zohar
On Fri, 2021-01-22 at 15:24 -0500, Paul Moore wrote: > On Thu, Jan 14, 2021 at 2:15 PM Lakshmi Ramasubramanian > wrote: > > > > SELinux stores the active policy in memory, so the changes to this data > > at runtime would have an impact on the security guarantees provided > > by SELinux. Measuring

Re: [PATCH] selinux: include a consumer of the new IMA critical data hook

2021-01-22 Thread Paul Moore
On Thu, Jan 14, 2021 at 2:15 PM Lakshmi Ramasubramanian wrote: > > SELinux stores the active policy in memory, so the changes to this data > at runtime would have an impact on the security guarantees provided > by SELinux. Measuring in-memory SELinux policy through IMA subsystem > provides a secu

Re: [PATCH] selinux: include a consumer of the new IMA critical data hook

2021-01-14 Thread Lakshmi Ramasubramanian
On 1/14/21 11:58 AM, Tyler Hicks wrote: On 2021-01-14 14:29:09, Paul Moore wrote: On Thu, Jan 14, 2021 at 2:15 PM Lakshmi Ramasubramanian wrote: SELinux stores the active policy in memory, so the changes to this data at runtime would have an impact on the security guarantees provided by SELin

Re: [PATCH] selinux: include a consumer of the new IMA critical data hook

2021-01-14 Thread Tyler Hicks
On 2021-01-14 14:29:09, Paul Moore wrote: > On Thu, Jan 14, 2021 at 2:15 PM Lakshmi Ramasubramanian > wrote: > > > > SELinux stores the active policy in memory, so the changes to this data > > at runtime would have an impact on the security guarantees provided > > by SELinux. Measuring in-memory

Re: [PATCH] selinux: include a consumer of the new IMA critical data hook

2021-01-14 Thread Paul Moore
On Thu, Jan 14, 2021 at 2:15 PM Lakshmi Ramasubramanian wrote: > > SELinux stores the active policy in memory, so the changes to this data > at runtime would have an impact on the security guarantees provided > by SELinux. Measuring in-memory SELinux policy through IMA subsystem > provides a secu

[PATCH] selinux: include a consumer of the new IMA critical data hook

2021-01-14 Thread Lakshmi Ramasubramanian
SELinux stores the active policy in memory, so the changes to this data at runtime would have an impact on the security guarantees provided by SELinux. Measuring in-memory SELinux policy through IMA subsystem provides a secure way for the attestation service to remotely validate the policy content